Authorization Bypass in ArcadeDB by ArcadeData
CVE-2026-67341
9.3CRITICAL
What is CVE-2026-67341?
ArcadeDB prior to version 26.7.2 is vulnerable to an authorization bypass that affects the handling of the SQL DEFINE FUNCTION statement using the JavaScript language. This vulnerability allows attackers who have database access to execute arbitrary JavaScript code by crafting and submitting malicious DEFINE FUNCTION statements. This security oversight undermines the intended access restrictions, granting unauthorized users the ability to perform actions typically reserved for administrators, posing significant risks to the integrity and security of database environments.
Affected Version(s)
arcadedb 0 < 26.7.2
arcadedb 26.7.2
