Access Control Bypass in ArcadeDB Versions Prior to 26.9.1
CVE-2026-93595
What is CVE-2026-93595?
ArcadeDB versions earlier than 26.9.1 are vulnerable to an access control bypass. This vulnerability exists within the query_database functionality that is exposed through AI chat interfaces. It permits authenticated users to execute database queries without properly enforcing the associated access controls. More specifically, the vulnerability allows users to circumvent per-type and per-bucket Access Control Lists (ACLs), leading to unauthorized access to sensitive data that they are usually restricted from viewing. Attackers can exploit this flaw by manipulating the AI assistant to issue queries against secured data types or buckets, thus retrieving sensitive information that would typically be denied through normal query methods.
Affected Version(s)
arcadedb 0 < 26.9.1
arcadedb 26.9.1
