CVE-2026-67356
published 2026-08-02CVE-2026-67356: ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.25%
16.1th percentile
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arcadedata | arcadedb | < 26.7.3 | 26.7.3 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ArcadeData ArcadeDB up to 26.7.2 JavaScript Trigger Context getSecurity.createUser privileges management (EUVD-2026-51986)
vuldb·2026-08-02·CVSS 8.8
CVE-2026-67356 [HIGH] ArcadeData ArcadeDB up to 26.7.2 JavaScript Trigger Context getSecurity.createUser privileges management (EUVD-2026-51986)
A vulnerability was found in ArcadeData ArcadeDB up to 26.7.2 and classified as critical. This affects the function getSecurity.createUser of the component JavaScript Trigger Context. Executing a manipulation can lead to improper privilege management.
The identification of this vulnerability is CVE-2026-67356. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks.
ghsa_unreviewed·2026-08-02
CVE-2026-67356 [HIGH] CWE-269 ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks.
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-02
Published