{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-67342/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-67341"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ArcadeDB"],"_cs_severities":["critical"],"_cs_tags":["authorization-bypass","cve-2026-67342"],"_cs_type":"advisory","_cs_vendors":["ArcadeData"],"content_html":"\u003cp\u003eArcadeDB versions prior to 26.7.2 are vulnerable to an authorization bypass flaw, tracked as CVE-2026-67341. The vulnerability exists within the SQL engine's handling of the \u003ccode\u003eDEFINE FUNCTION\u003c/code\u003e command when the \u003ccode\u003eLANGUAGE\u003c/code\u003e parameter is set to \u003ccode\u003ejs\u003c/code\u003e. The application fails to properly enforce security checks that should restrict the registration of functions to administrative users. An attacker with database access can leverage this defect to register and execute arbitrary JavaScript code. This vulnerability has a critical impact, potentially allowing for full system compromise or unauthorized access to sensitive database data, as the code executes within the context of the database process.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes a connection to the target ArcadeDB instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious SQL \u003ccode\u003eDEFINE FUNCTION\u003c/code\u003e statement specifying \u003ccode\u003eLANGUAGE js\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker embeds arbitrary JavaScript payload into the function body.\u003c/li\u003e\n\u003cli\u003eAttacker executes the SQL statement against the target database.\u003c/li\u003e\n\u003cli\u003eThe ArcadeDB engine fails to validate the user's authorization level for the \u003ccode\u003eDEFINE FUNCTION\u003c/code\u003e operation.\u003c/li\u003e\n\u003cli\u003eThe database engine registers the malicious function.\u003c/li\u003e\n\u003cli\u003eAttacker invokes the newly created function to execute the malicious JavaScript payload.\u003c/li\u003e\n\u003cli\u003eAttacker achieves command execution within the database engine context.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized users to achieve arbitrary code execution within the database engine. This can lead to full compromise of the database integrity, confidentiality, and availability, depending on the permissions of the database process. The vulnerability affects all ArcadeDB deployments running versions prior to 26.7.2.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all ArcadeDB instances to version 26.7.2 or later immediately to address the authorization check failure.\u003c/li\u003e\n\u003cli\u003eAudit database logs for the usage of the \u003ccode\u003eDEFINE FUNCTION\u003c/code\u003e command, specifically looking for JavaScript-based functions created by non-administrative service accounts.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the ArcadeDB management ports to prevent unauthorized actors from reaching the database interface.\u003c/li\u003e\n\u003cli\u003eMonitor database activity for unexpected execution of custom functions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T13:55:04Z","date_published":"2026-08-01T13:51:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-arcadedb-auth-bypass/","summary":"ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability (CVE-2026-67341) that permits unprivileged users to execute arbitrary JavaScript code via the DEFINE FUNCTION statement.","title":"Authorization Bypass in ArcadeDB SQL DEFINE FUNCTION","url":"https://feed.craftedsignal.io/briefs/2026-08-arcadedb-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-67342","version":"https://jsonfeed.org/version/1.1"}