PT-2026-95373 · Arcadedb · Arcadedb

·

CVE-2026-93594

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.9.1
Description Access-control rules for per-type and per-record permissions are only enforced in LocalBucket. Query-execution paths accessing record data via LSM (Log-Structured Merge-tree) index files or the TimeSeries engine bypass these permission checks. Consequently, an authenticated user without readRecord or deleteRecord permissions can use SQL statements to read indexed key values, record IDs, and MAX/MIN values, as well as read and count TimeSeries samples and determine the total record count. Additionally, users can delete index entries, which desynchronizes the index from the data and may bypass unique constraints. The necessary index and type names are discoverable because the SELECT FROM schema:indexes query is unfiltered. This issue impacts embedded and server deployments across all transports, including HTTP, Bolt, Postgres, and Gremlin, once a principal is bound.
Recommendations Update to version 26.9.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93594
GHSA-2C8M-Q484-JV7M

Affected Products

Arcadedb