Product
ArcadeDB versions 26.7.3 and earlier are vulnerable to a missing authorization flaw allowing any authenticated database user to delete server-side functions via the command API.