Impact
ArcadeDB versions prior to 26.8.1 do not correctly associate the authenticated user with batch and time‑series HTTP request handlers. Because the principal is missing on the worker thread, the fine‑grained per‑type ACL checks are skipped. An attacker who has database access but limited per‑type permissions can send requests to the batch or time‑series endpoints and read or write records in types that should be protected. The vulnerability is a CWE‑862 problem of improper authorization.
Affected Systems
This issue affects all installations of ArcadeDB released before 26.8.1. Existing deployments that rely exclusively on database‑level permissions are safe, but any configuration that enables per‑type or per‑group ACLs is vulnerable. The vendor is ArcadeData, product ArcadeDB.
Risk and Exploitability
The CVSS score of 2.3 reflects the limited impact, but the lack of an authenticated or exploit check indicates the vulnerability is exploitable over the network via standard HTTP batch or time‑series APIs. No EPSS score is available and the flaw is not listed in the CISA KEV catalog, suggesting it has not yet been actively abused. In environments that allow these endpoints, an attacker can gain unauthorized data access, so the risk is low severity but potentially significant for protected data.
OpenCVE Enrichment