Impact
ArcadeDB versions earlier than 26.9.1 have a flaw in the query_database tool exposed through the AI chat endpoints. The tool runs queries without tying the authenticated principal to the DatabaseContext, which causes type‑level and bucket‑level ACL checks to be bypassed silently. As a result, an authenticated user may read data from types or buckets that are otherwise denied, leading to untrusted data disclosure. The weakness is a classic access control bypass (CWE‑862).
Affected Systems
The affected product is ArcadeData ArcadeDB. Any deployment running ArcadeDB versions before 26.9.1 is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a medium severity risk. The EPSS score of 0.00286 indicates a very low but non-zero probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. Attackers must authenticate and use the AI chat interface to issue a query_database command; failure to perform proper ACL checks allows them to extract sensitive data that would normally be blocked on normal query endpoints.
OpenCVE Enrichment