CVE-2026-67341
published 2026-08-01CVE-2026-67341: ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database…
PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.32%
25.1th percentile
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arcadedata | arcadedb | < 26.7.2 | 26.7.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ArcadeData ArcadeDB up to 26.7.1 improper authorization (EUVD-2026-51832)
vuldb·2026-08-01·CVSS 9.8
CVE-2026-67341 [CRITICAL] ArcadeData ArcadeDB up to 26.7.1 improper authorization (EUVD-2026-51832)
A vulnerability classified as critical was found in ArcadeData ArcadeDB up to 26.7.1. This affects an unknown function. Executing a manipulation can lead to improper authorization.
The identification of this vulnerability is CVE-2026-67341. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js.
ghsa_unreviewed·2026-08-01
CVE-2026-67341 [CRITICAL] CWE-863 ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js.
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-01
Published