Description
ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privilege user can read or insert TimeSeries samples despite explicit deny rules by exploiting the missing type-name-based access check that causes permission lookups to fail open.
Published: 2026-09-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized read or insert of TimeSeries data
Action: Patch ASAP
AI Analysis

Impact

ArcadeDB fails to enforce security‑group type ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, which TimeSeries types do not use. As a result, an authenticated user with low privileges can read or insert TimeSeries samples even when explicit deny rules are present, owing to a missing type‑name access check that causes permission lookups to fail open. This vulnerability permits unauthorized disclosure of sensor or metric data and potential tampering with time‑series entries.

Affected Systems

ArcadeData’s ArcadeDB is affected in all releases prior to version 26.9.1. Any deployment using those versions that exposes TimeSeries types is vulnerable.

Risk and Exploitability

The CVSS score of 8.6 classifies the issue as high severity. EPSS data indicates a probability below 1%, suggesting the vulnerability is considered unlikely to be exploited in the wild. The vulnerability requires only an authenticated low‑privilege account and no special conditions, enabling an attacker to read or insert TimeSeries samples despite explicit deny rules. The flaw is not listed in CISA’s KEV catalog. Given the high score and the ability to read or inject data, the overall risk to confidentiality and integrity remains significant.

Generated by OpenCVE AI on September 19, 2026 at 19:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ArcadeDB to version 26.9.1 or later, which implements proper ACL enforcement for TimeSeries types.
  • If an upgrade cannot be performed immediately, disable or restrict network access to TimeSeries type usage until the fix is applied.
  • Review and tighten ACL configurations to ensure that TimeSeries entries have explicit deny rules for unauthorized users and remove any overly permissive entries.

Generated by OpenCVE AI on September 19, 2026 at 19:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Arcadedata
Arcadedata arcadedb
Vendors & Products Arcadedata
Arcadedata arcadedb

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privilege user can read or insert TimeSeries samples despite explicit deny rules by exploiting the missing type-name-based access check that causes permission lookups to fail open.
Title ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Arcadedata Arcadedb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T14:21:01.126Z

Reserved: 2026-09-18T10:59:45.138Z

Link: CVE-2026-93593

cve-icon Vulnrichment

Updated: 2026-09-22T14:20:56.046Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:10.413

Modified: 2026-09-22T15:17:23.783

Link: CVE-2026-93593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:45:11Z

Weaknesses