Permission Bypass Vulnerability in ArcadeDB by ArcadeData
CVE-2026-76223

7.1HIGH

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76223?

ArcadeDB versions 26.7.3 and earlier contain a flaw in enforcing permission checks during function library modifications. This enables users with basic database access to add or overwrite SQL or Cypher functions within existing libraries, potentially compromising the intended logic of admin-defined functions. The vulnerability has been addressed in version 26.8.1, which restricts these actions but still allows JavaScript functions to trigger the existing UPDATE_SECURITY checks.

Affected Version(s)

arcadedb 0 < 26.8.1

arcadedb 26.8.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.