Impact
ArcadeDB is a multi‑model database management system. Before version 26.6.1, the fix for CVE‑2026‑44221 added an UPDATE_SCHEMA permission check only to the LocalDocumentType.createProperty method, leaving other public schema mutator methods unchecked. As a result, an authenticated identity—even one with a read‑only API token lacking UPDATE_SCHEMA permission—could issue schema‑altering commands such as DROP PROPERTY, ALTER TYPE, or ALTER PROPERTY through the database command/query HTTP endpoints. These commands can rename types, change inheritance, alter aliases or buckets, drop properties, and adjust property constraints. Although the flaw does not directly expose or modify record data, it allows unauthorized schema changes that can corrupt the meaning of stored records and violate the intended permission model.
Affected Systems
The flaw affects ArcadeData's ArcadeDB (including the arcadedb-engine module). All releases prior to 26.6.1 are vulnerable; the issue was resolved in version 26.6.1 and later.
Risk and Exploitability
The CVSS score is 8.1, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Affected users must have authenticated access and read‑only tokens; the likely attack vector is the database command/query HTTP endpoint. Any user capable of authenticating to the database could exploit the flaw, potentially resulting in significant operational impact if not patch‑up‑to‑date.
OpenCVE Enrichment
Github GHSA