Impact
ArcadeDB fails to enforce security‑group type ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, which TimeSeries types do not use. As a result, an authenticated user with low privileges can read or insert TimeSeries samples even when explicit deny rules are present, owing to a missing type‑name access check that causes permission lookups to fail open. This vulnerability permits unauthorized disclosure of sensor or metric data and potential tampering with time‑series entries.
Affected Systems
ArcadeData’s ArcadeDB is affected in all releases prior to version 26.9.1. Any deployment using those versions that exposes TimeSeries types is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies the issue as high severity. EPSS data indicates a probability below 1%, suggesting the vulnerability is considered unlikely to be exploited in the wild. The vulnerability requires only an authenticated low‑privilege account and no special conditions, enabling an attacker to read or insert TimeSeries samples despite explicit deny rules. The flaw is not listed in CISA’s KEV catalog. Given the high score and the ability to read or inject data, the overall risk to confidentiality and integrity remains significant.
OpenCVE Enrichment