{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-68578/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-67356"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ArcadeDB","ArcadeDB (\u003c 26.7.3)"],"_cs_severities":["high"],"_cs_tags":["information-disclosure","privilege-escalation","database","authentication-bypass","database-security","cve-2026-68578"],"_cs_type":"advisory","_cs_vendors":["ArcadeData"],"content_html":"\u003cp\u003eArcadeDB versions prior to 26.7.3 contain a security flaw where the \u003ccode\u003eLocalDatabase\u003c/code\u003e object is bound into JavaScript trigger contexts with \u003ccode\u003eHostAccess.ALL\u003c/code\u003e. This misconfiguration allows users with the \u003ccode\u003eUPDATE_SCHEMA\u003c/code\u003e permission to execute arbitrary JavaScript code that bypasses the security manager. Specifically, an authenticated attacker can invoke sensitive methods such as \u003ccode\u003egetSecurity().createUser()\u003c/code\u003e without appropriate authorization checks. By creating a malicious database trigger, a low-privileged user can escalate their privileges to become a server-wide administrator. This vulnerability (CVE-2026-67356) represents a significant risk for environments where database schema management is delegated to non-administrative users.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the ArcadeDB instance with valid credentials possessing \u003ccode\u003eUPDATE_SCHEMA\u003c/code\u003e permissions.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the database management API or console to define a new JavaScript trigger.\u003c/li\u003e\n\u003cli\u003eThe trigger is crafted to invoke the insecurely bound \u003ccode\u003eLocalDatabase\u003c/code\u003e object.\u003c/li\u003e\n\u003cli\u003eThe JavaScript execution context uses \u003ccode\u003eHostAccess.ALL\u003c/code\u003e, providing the script unrestricted access to core internal objects.\u003c/li\u003e\n\u003cli\u003eThe attacker's script calls \u003ccode\u003egetSecurity().createUser()\u003c/code\u003e to provision a new administrative user.\u003c/li\u003e\n\u003cli\u003eThe application fails to enforce permission checks during the method invocation due to the exposed context.\u003c/li\u003e\n\u003cli\u003eA new account with administrative privileges is created.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates with the newly created admin account to achieve full server compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to gain full administrative control over the ArcadeDB server. This can lead to complete data exfiltration, unauthorized modification or deletion of all databases, and persistent access to the underlying infrastructure. Organizations relying on ArcadeDB for critical data storage are at high risk if schema modification permissions are assigned to users who are not fully trusted.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade ArcadeDB to version 26.7.3 or later immediately to restrict \u003ccode\u003eHostAccess\u003c/code\u003e bindings in JavaScript contexts.\u003c/li\u003e\n\u003cli\u003eReview current user role assignments and revoke \u003ccode\u003eUPDATE_SCHEMA\u003c/code\u003e permissions from any user accounts that do not require them.\u003c/li\u003e\n\u003cli\u003eAudit database triggers for suspicious JavaScript code that interacts with the \u003ccode\u003egetSecurity()\u003c/code\u003e or \u003ccode\u003ecreateUser()\u003c/code\u003e methods.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-02T13:36:13Z","date_published":"2026-08-02T13:35:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-arcadedb-privilege-escalation/","summary":"ArcadeDB versions before 26.7.3 insecurely expose the LocalDatabase object to JavaScript triggers, allowing attackers with schema update permissions to perform unauthorized administrative actions.","title":"ArcadeDB Privilege Escalation via JavaScript Triggers","url":"https://feed.craftedsignal.io/briefs/2026-08-arcadedb-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-68578","version":"https://jsonfeed.org/version/1.1"}