Description
ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}. Because those workers have no current user, LocalDatabase.checkPermissionsOnFile returns early and allows the write, bypassing per-type CREATE_RECORD/UPDATE_RECORD ACL enforcement. In deployments that rely on per-type or per-group ACLs, an authenticated low-privilege user holding CREATE_RECORD on an edge type E but with CREATE_RECORD/UPDATE_RECORD revoked on a vertex type V can submit a graph edge-load batch request (with parallelFlush at its default value of true) and durably append edges to protected vertices of type V by writing records into V's <V>_out_edges/<V>_in_edges buckets, resulting in unauthorized modification of graph adjacency. Setting parallelFlush=false causes the request to be correctly rejected. This is an incomplete fix of GHSA-c23x-pqcj-7hfm, which bound the principal only on the HTTP handler thread.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass leading to unauthorized edge writes
Action: Patch ASAP
AI Analysis

Impact

ArcadeDB fails to propagate the authenticated user to async worker threads during the batch edge‑connect phase of POST /api/v1/batch/{database}. As a result, the permission check for write operations is bypassed, allowing an authenticated user with only edge‑type CREATE_RECORD privileges to create records in vertex types that have those privileges revoked. The attacker can therefore insert edges that connect to protected vertices and manipulate graph adjacency that should be restricted by per‑type or per‑group ACLs. This is a classic authorization bypass (CWE‑862) that results in unauthorized modification of data integrity.

Affected Systems

The vulnerability exists in ArcadeData ArcadeDB versions before 26.9.1, specifically com.arcadedb:arcadedb-engine <= 26.8.1. Users running legacy ArcadeDB deployments that expose the batch endpoint are affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is < 1 % and the vulnerability is not listed in CISA's KEV catalog, indicating low likelihood of exploitation but no known public exploits. The likely attack vector is an HTTP POST request to the /api/v1/batch/{database} endpoint from a client that can authenticate but has low privileges. The attacker would need the batch endpoint to be externally reachable and the ‘parallelFlush’ setting to remain at its default true; setting parallelFlush=false mitigates the issue.

Generated by OpenCVE AI on September 19, 2026 at 19:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official ArcadeDB 26.9.1 or later patch to bind the authenticated principal to async worker threads.
  • If an immediate patch is not possible, configure the batch endpoint to use parallelFlush=false to prevent unauthorized edge writes.
  • Ensure per‑type ACLs grant the same or fewer permissions to the low‑privilege user or restrict the batch endpoint access with firewall rules.

Generated by OpenCVE AI on September 19, 2026 at 19:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Arcadedata
Arcadedata arcadedb
Vendors & Products Arcadedata
Arcadedata arcadedb

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}. Because those workers have no current user, LocalDatabase.checkPermissionsOnFile returns early and allows the write, bypassing per-type CREATE_RECORD/UPDATE_RECORD ACL enforcement. In deployments that rely on per-type or per-group ACLs, an authenticated low-privilege user holding CREATE_RECORD on an edge type E but with CREATE_RECORD/UPDATE_RECORD revoked on a vertex type V can submit a graph edge-load batch request (with parallelFlush at its default value of true) and durably append edges to protected vertices of type V by writing records into V's <V>_out_edges/<V>_in_edges buckets, resulting in unauthorized modification of graph adjacency. Setting parallelFlush=false causes the request to be correctly rejected. This is an incomplete fix of GHSA-c23x-pqcj-7hfm, which bound the principal only on the HTTP handler thread.
Title ArcadeDB before 26.9.1 Authorization Bypass via Batch Edge Connect
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Arcadedata Arcadedb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:50:53.987Z

Reserved: 2026-09-18T11:00:32.755Z

Link: CVE-2026-93596

cve-icon Vulnrichment

Updated: 2026-09-18T17:50:47.683Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:10.917

Modified: 2026-09-18T18:18:29.093

Link: CVE-2026-93596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:45:11Z

Weaknesses