Authorization Bypass in ArcadeDB Affects Multiple HTTP Handlers
CVE-2026-67342
9.3CRITICAL
What is CVE-2026-67342?
ArcadeDB versions prior to 26.7.2 contain an authorization bypass flaw in several HTTP handlers associated with time series, batch, Prometheus, and Grafana endpoints. This weakness arises from the lack of proper validation for database access permissions, allowing unauthorized attackers to manipulate and access databases simply by invoking the affected endpoints with arbitrary parameters. It emphasizes the importance of stringent access controls and thorough validation processes to protect sensitive data from exploitation.
Affected Version(s)
arcadedb 0 < 26.7.2
arcadedb 26.7.2
