PT-2026-95374 · Arcadedb · Arcadedb
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.9.1
Description
An access control bypass exists in the
query database tool exposed through the AI chat endpoints. The tool executes queries without binding the authenticated principal to the DatabaseContext, which causes Access Control List (ACL) checks for specific types and buckets to be ignored. This allows authenticated users to retrieve sensitive data from restricted types or buckets by prompting the AI assistant, bypassing the restrictions enforced on normal query endpoints.Recommendations
Update ArcadeDB to version 26.9.1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb