PT-2026-95375 · Arcadedb · Arcadedb

·

CVE-2026-93596

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.9.1
Description An issue exists where the system fails to bind the authenticated principal to the DatabaseAsyncTransaction async worker threads during the parallel edge-connect phase of the 'POST /api/v1/batch/{database}' endpoint. Consequently, the LocalDatabase.checkPermissionsOnFile() function returns early, allowing write operations that bypass per-type CREATE RECORD and UPDATE RECORD Access Control List (ACL) enforcement. An authenticated user with low privileges who has CREATE RECORD permissions on an edge type but lacks them for a vertex type can submit a graph edge-load batch request. If the parallelFlush variable is set to its default value of true, the user can append edges to protected vertices by writing records into the <V> out edges or <V> in edges buckets, leading to unauthorized modification of graph adjacency.
Recommendations Update to version 26.9.1 or later. As a temporary workaround, set the parallelFlush variable to false to ensure requests are correctly rejected.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93596
GHSA-27VW-J8QC-5H7X

Affected Products

Arcadedb