PT-2026-95374 · Arcadedb · Arcadedb

·

CVE-2026-93595

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.9.1
Description An access control bypass exists in the query database tool exposed through the AI chat endpoints. The tool executes queries without binding the authenticated principal to the DatabaseContext, which causes Access Control List (ACL) checks for specific types and buckets to be ignored. This allows authenticated users to retrieve sensitive data from restricted types or buckets by prompting the AI assistant, bypassing the restrictions enforced on normal query endpoints.
Recommendations Update ArcadeDB to version 26.9.1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93595
GHSA-CHRR-VR3P-CRCC

Affected Products

Arcadedb