PT-2026-95375 · Arcadedb · Arcadedb
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.9.1
Description
An issue exists where the system fails to bind the authenticated principal to the
DatabaseAsyncTransaction async worker threads during the parallel edge-connect phase of the 'POST /api/v1/batch/{database}' endpoint. Consequently, the LocalDatabase.checkPermissionsOnFile() function returns early, allowing write operations that bypass per-type CREATE RECORD and UPDATE RECORD Access Control List (ACL) enforcement. An authenticated user with low privileges who has CREATE RECORD permissions on an edge type but lacks them for a vertex type can submit a graph edge-load batch request. If the parallelFlush variable is set to its default value of true, the user can append edges to protected vertices by writing records into the <V> out edges or <V> in edges buckets, leading to unauthorized modification of graph adjacency.Recommendations
Update to version 26.9.1 or later.
As a temporary workaround, set the
parallelFlush variable to false to ensure requests are correctly rejected.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb