Authorization Bypass in ArcadeDB Affects Multiple HTTP Handlers
CVE-2026-67342

9.3CRITICAL

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67342?

ArcadeDB versions prior to 26.7.2 contain an authorization bypass flaw in several HTTP handlers associated with time series, batch, Prometheus, and Grafana endpoints. This weakness arises from the lack of proper validation for database access permissions, allowing unauthorized attackers to manipulate and access databases simply by invoking the affected endpoints with arbitrary parameters. It emphasizes the importance of stringent access controls and thorough validation processes to protect sensitive data from exploitation.

Affected Version(s)

arcadedb 0 < 26.7.2

arcadedb 26.7.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.