Product
high
advisory
ArcadeDB Privilege Escalation via JavaScript Triggers
1 rule 3 TTPs 1 CVEArcadeDB versions before 26.7.3 insecurely expose the LocalDatabase object to JavaScript triggers, allowing attackers with schema update permissions to perform unauthorized administrative actions.
ArcadeDB +1
information-disclosure
privilege-escalation
database
authentication-bypass
database-security
cve-2026-68578
1r
3t
1c
critical
advisory
Authorization Bypass in ArcadeDB SQL DEFINE FUNCTION
2 rules 2 TTPs 1 CVEArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability (CVE-2026-67341) that permits unprivileged users to execute arbitrary JavaScript code via the DEFINE FUNCTION statement.
ArcadeDB
authorization-bypass
cve-2026-67342
2r
2t
1c
critical
advisory
ArcadeDB Authorization Bypass Vulnerability
2 rules 2 TTPs 1 CVEArcadeDB versions prior to 26.4.2 are vulnerable to an authorization bypass, allowing authenticated users and API tokens scoped to a specific database to read, write, and mutate schema on any other database on the same server, and disabling the record-level authorization system for newly created databases.
arcadedb-server +2
authorization bypass
privilege escalation
cve-2026-44221
2r
2t
1c
updated