CVE-2026-44221
published 2026-05-12CVE-2026-44221: ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could…
PriorityP354critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
0.40%
33.7th percentile
ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestAccessOnFile treated as allow-all; (2) ArcadeDBServer.createDatabase() omitted factory.setSecurity(...) so any database created via POST /api/v1/server {"command":"create database X"} had its entire record-level authorization system silently disabled. In combination, record-level and database-level authorization could be bypassed by any authenticated principal. This vulnerability is fixed in 26.4.2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arcadedata | arcadedb | < 26.7.1 | 26.7.1 |
| com.arcadedb | arcadedb-server | < 26.7.1 | 26.7.1 |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
ghsa9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
ghsa·2026-07-16·CVSS 9.0
CVE-2026-44221 [CRITICAL] CWE-269 ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
### Impact
A user holding only `reader` (read-only) privileges on a single database could execute arbitrary JVM code by sending a `"language": "js"` command to the `POST /api/v1/command/{database}` HTTP endpoint, and use it to read arbitrary files on the host filesystem (e.g. `/etc/passwd`, configuration files), outside the scope of the database itself.
Two cooperating defects made this possible:
1. **Missing authorization on the scripting path (CWE-863 / CWE-269).** Polyglot script execution (`js` and other GraalVM languages) never went through the database authorization checks applied to SQL/Cypher, so any authenticated principal - regardless of database role - could run
GHSA
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
ghsa·2026-07-16·CVSS 9.0
CVE-2026-54076 [CRITICAL] CWE-862 ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
### Impact
The fix for CVE-2026-44221 (GHSA-fxc7-fm93-6q77) added an `UPDATE_SCHEMA` authorization check to a single schema-mutating method (`LocalDocumentType.createProperty`). The remaining public schema mutators were left unchecked, so an authenticated identity (including a **read-only API token**) that lacks the `UPDATE_SCHEMA` permission could still mutate the database schema on its own database:
- `DROP PROPERTY .`
- `ALTER TYPE SUPERTYPE +` / `-` (change the inheritance hierarchy)
- `ALTER TYPE NAME ` (rename a type)
- type alias and bucket changes
- `ALTER PROPERTY . ...` (MANDATORY, READONLY, NOTNULL, MIN, MAX, REGEXP, DEFAULT, OF, CUSTOM) — the `LocalProperty` setters had no check at all
T
VulDB
ArcadeData arcadedb up to 2.6.3 ServerSecurityUser.getDatabaseUser authorization (GHSA-fxc7-fm93-6q77)
vuldb·2026-05-12
CVE-2026-44221 [CRITICAL] ArcadeData arcadedb up to 2.6.3 ServerSecurityUser.getDatabaseUser authorization (GHSA-fxc7-fm93-6q77)
A vulnerability was found in ArcadeData arcadedb up to 2.6.3. It has been rated as critical. The affected element is the function ServerSecurityUser.getDatabaseUser. This manipulation causes incorrect authorization.
This vulnerability is handled as CVE-2026-44221. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
ghsa·2026-05-05
CVE-2026-44221 [CRITICAL] CWE-863 ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
### Impact
Authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestAccessOnFile treated as allow-all; (2) ArcadeDBServer.createDatabase() omitted factory.setSecurity(...) so any database created via POST /api/v1/server {"command":"create database X"} had its entire record-level authorization system silently disabled. In combination, record-level and database-level authorization could be bypassed by any authenticated principal.
### Patches
Upgrade to version 26.4.2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-12
Published