Description
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or the TimeSeries engine never invoke that permission check, so an authenticated user who is denied readRecord/deleteRecord on a type can still, with a single ordinary SQL statement, read the type's indexed key values and record IDs (e.g. SELECT key, rid FROM INDEX:Type[field]), read MAX/MIN values via the index shortcut, read and count TimeSeries samples, learn the type's record count, and delete index entries (DELETE FROM INDEX:Type[field]), which desynchronizes the index from the data and can defeat unique constraints. Index and type names needed for exploitation are discoverable because SELECT FROM schema:indexes is unfiltered. The issue affects both embedded and server deployments and all transports (HTTP, Bolt, Postgres, Gremlin) once a principal is bound. Fixed in 26.9.1.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Access Control Bypass
Action: Immediate Patch
AI Analysis

Impact

ArcadeDB enforces per-type/per-record access controls only within the LocalBucket component, but routes that use LSM index files or the TimeSeries engine skip these checks. As a result, an authenticated user lacking permissions on a particular type can read or delete data through SQL statements that target the index or timeseries, exposing key values, record identifiers, and sample counts, and potentially corrupting the index. This flaw is an instance of CWE-863: Incorrect Access Control.

Affected Systems

ArcadeData's ArcadeDB database, versions prior to 26.9.1, deployed in both embedded and server modes and accessed via HTTP, Bolt, PostgreSQL, or Gremlin protocols.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑high severity. With an EPSS score of 0.00337, the likelihood cannot be quantified, but the vulnerability is not listed in CISA's KEV catalog, suggesting no known exploits. An attacker must be authenticated, so the primary attack vector is an authenticated privileged user. Based on the description, it is inferred that the flaw can be exploited by executing standard SQL statements that reference the index or time series, bypassing ACL checks.

Generated by OpenCVE AI on September 19, 2026 at 19:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ArcadeDB to version 26.9.1 or later to apply the ACL bypass fix.
  • Review and tighten ACL configurations to ensure that only authorized roles can query index and timeseries features.
  • If an immediate upgrade is not feasible, limit database exposure to a trusted network segment and monitor for anomalous index or timeseries queries as a temporary mitigation.

Generated by OpenCVE AI on September 19, 2026 at 19:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Arcadedata
Arcadedata arcadedb
Vendors & Products Arcadedata
Arcadedata arcadedb

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or the TimeSeries engine never invoke that permission check, so an authenticated user who is denied readRecord/deleteRecord on a type can still, with a single ordinary SQL statement, read the type's indexed key values and record IDs (e.g. SELECT key, rid FROM INDEX:Type[field]), read MAX/MIN values via the index shortcut, read and count TimeSeries samples, learn the type's record count, and delete index entries (DELETE FROM INDEX:Type[field]), which desynchronizes the index from the data and can defeat unique constraints. Index and type names needed for exploitation are discoverable because SELECT FROM schema:indexes is unfiltered. The issue affects both embedded and server deployments and all transports (HTTP, Bolt, Postgres, Gremlin) once a principal is bound. Fixed in 26.9.1.
Title ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Arcadedata Arcadedb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T14:32:33.083Z

Reserved: 2026-09-18T10:59:45.138Z

Link: CVE-2026-93594

cve-icon Vulnrichment

Updated: 2026-09-18T14:32:21.936Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:10.587

Modified: 2026-09-18T15:17:21.587

Link: CVE-2026-93594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:45:11Z

Weaknesses