Impact
ArcadeDB enforces per-type/per-record access controls only within the LocalBucket component, but routes that use LSM index files or the TimeSeries engine skip these checks. As a result, an authenticated user lacking permissions on a particular type can read or delete data through SQL statements that target the index or timeseries, exposing key values, record identifiers, and sample counts, and potentially corrupting the index. This flaw is an instance of CWE-863: Incorrect Access Control.
Affected Systems
ArcadeData's ArcadeDB database, versions prior to 26.9.1, deployed in both embedded and server modes and accessed via HTTP, Bolt, PostgreSQL, or Gremlin protocols.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑high severity. With an EPSS score of 0.00337, the likelihood cannot be quantified, but the vulnerability is not listed in CISA's KEV catalog, suggesting no known exploits. An attacker must be authenticated, so the primary attack vector is an authenticated privileged user. Based on the description, it is inferred that the flaw can be exploited by executing standard SQL statements that reference the index or time series, bypassing ACL checks.
OpenCVE Enrichment