Authorization Bypass in ArcadeDB by ArcadeData
CVE-2026-67341

9.3CRITICAL

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67341?

ArcadeDB prior to version 26.7.2 is vulnerable to an authorization bypass that affects the handling of the SQL DEFINE FUNCTION statement using the JavaScript language. This vulnerability allows attackers who have database access to execute arbitrary JavaScript code by crafting and submitting malicious DEFINE FUNCTION statements. This security oversight undermines the intended access restrictions, granting unauthorized users the ability to perform actions typically reserved for administrators, posing significant risks to the integrity and security of database environments.

Affected Version(s)

arcadedb 0 < 26.7.2

arcadedb 26.7.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.