Description
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcadedb/schema/LocalDocumentType.java and engine/src/main/java/com/arcadedb/schema/LocalProperty.java remained unchecked. An authenticated identity, including a read-only API token without UPDATE_SCHEMA permission, can use DROP PROPERTY, ALTER TYPE, or ALTER PROPERTY through the database command/query HTTP endpoints to rename types, change inheritance, alter aliases or buckets, drop properties, and change property constraints. The issue does not directly disclose or write record data, but unauthorized schema mutation can corrupt the meaning of stored records and breach the documented permission model. This issue is fixed in version 26.6.1.
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Schema Modification by Read‑Only Users
Action: Apply Patch
AI Analysis

Impact

ArcadeDB is a multi‑model database management system. Before version 26.6.1, the fix for CVE‑2026‑44221 added an UPDATE_SCHEMA permission check only to the LocalDocumentType.createProperty method, leaving other public schema mutator methods unchecked. As a result, an authenticated identity—even one with a read‑only API token lacking UPDATE_SCHEMA permission—could issue schema‑altering commands such as DROP PROPERTY, ALTER TYPE, or ALTER PROPERTY through the database command/query HTTP endpoints. These commands can rename types, change inheritance, alter aliases or buckets, drop properties, and adjust property constraints. Although the flaw does not directly expose or modify record data, it allows unauthorized schema changes that can corrupt the meaning of stored records and violate the intended permission model.

Affected Systems

The flaw affects ArcadeData's ArcadeDB (including the arcadedb-engine module). All releases prior to 26.6.1 are vulnerable; the issue was resolved in version 26.6.1 and later.

Risk and Exploitability

The CVSS score is 8.1, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Affected users must have authenticated access and read‑only tokens; the likely attack vector is the database command/query HTTP endpoint. Any user capable of authenticating to the database could exploit the flaw, potentially resulting in significant operational impact if not patch‑up‑to‑date.

Generated by OpenCVE AI on September 20, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ArcadeDB to version 26.6.1 or later
  • Identify and remove or re‑configure any read‑only permissions for UPDATE_SCHEMA
  • If an upgrade is not yet possible, disable or restrict access to the schema mutation commands on the HTTP API using firewall or proxy rules

Generated by OpenCVE AI on September 20, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vg6x-6pg9-6qwg ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Arcadedata
Arcadedata arcadedb
Vendors & Products Arcadedata
Arcadedata arcadedb

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcadedb/schema/LocalDocumentType.java and engine/src/main/java/com/arcadedb/schema/LocalProperty.java remained unchecked. An authenticated identity, including a read-only API token without UPDATE_SCHEMA permission, can use DROP PROPERTY, ALTER TYPE, or ALTER PROPERTY through the database command/query HTTP endpoints to rename types, change inheritance, alter aliases or buckets, drop properties, and change property constraints. The issue does not directly disclose or write record data, but unauthorized schema mutation can corrupt the meaning of stored records and breach the documented permission model. This issue is fixed in version 26.6.1.
Title ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
Weaknesses CWE-862
CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Arcadedata Arcadedb
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T17:12:34.605Z

Reserved: 2026-06-11T18:44:47.760Z

Link: CVE-2026-54076

cve-icon Vulnrichment

Updated: 2026-09-15T17:12:06.507Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:13.560

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:30:18Z

Weaknesses