Impact
ArcadeDB fails to propagate the authenticated user to async worker threads during the batch edge‑connect phase of POST /api/v1/batch/{database}. As a result, the permission check for write operations is bypassed, allowing an authenticated user with only edge‑type CREATE_RECORD privileges to create records in vertex types that have those privileges revoked. The attacker can therefore insert edges that connect to protected vertices and manipulate graph adjacency that should be restricted by per‑type or per‑group ACLs. This is a classic authorization bypass (CWE‑862) that results in unauthorized modification of data integrity.
Affected Systems
The vulnerability exists in ArcadeData ArcadeDB versions before 26.9.1, specifically com.arcadedb:arcadedb-engine <= 26.8.1. Users running legacy ArcadeDB deployments that expose the batch endpoint are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is < 1 % and the vulnerability is not listed in CISA's KEV catalog, indicating low likelihood of exploitation but no known public exploits. The likely attack vector is an HTTP POST request to the /api/v1/batch/{database} endpoint from a client that can authenticate but has low privileges. The attacker would need the batch endpoint to be externally reachable and the ‘parallelFlush’ setting to remain at its default true; setting parallelFlush=false mitigates the issue.
OpenCVE Enrichment