Access Control Bypass in ArcadeDB Versions Prior to 26.9.1
CVE-2026-93595

7.1HIGH

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93595?

ArcadeDB versions earlier than 26.9.1 are vulnerable to an access control bypass. This vulnerability exists within the query_database functionality that is exposed through AI chat interfaces. It permits authenticated users to execute database queries without properly enforcing the associated access controls. More specifically, the vulnerability allows users to circumvent per-type and per-bucket Access Control Lists (ACLs), leading to unauthorized access to sensitive data that they are usually restricted from viewing. Attackers can exploit this flaw by manipulating the AI assistant to issue queries against secured data types or buckets, thus retrieving sensitive information that would typically be denied through normal query methods.

Affected Version(s)

arcadedb 0 < 26.9.1

arcadedb 26.9.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

T4ran24
.