Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fxc7-fm93-6q77 | ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases |
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arcadedata
Arcadedata arcadedb |
|
| Vendors & Products |
Arcadedata
Arcadedata arcadedb |
Tue, 12 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ArcadeDB is a Multi-Model DBMS. Prior to 2.6.4, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestAccessOnFile treated as allow-all; (2) ArcadeDBServer.createDatabase() omitted factory.setSecurity(...) so any database created via POST /api/v1/server {"command":"create database X"} had its entire record-level authorization system silently disabled. In combination, record-level and database-level authorization could be bypassed by any authenticated principal. This vulnerability is fixed in 2.6.4. | |
| Title | ArcadeDB: Cross-database authorization bypass and unsecured newly-created databases | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T14:48:45.728Z
Reserved: 2026-05-05T15:42:40.518Z
Link: CVE-2026-44221
Updated: 2026-05-13T14:48:42.442Z
Status : Deferred
Published: 2026-05-12T20:16:43.020
Modified: 2026-05-13T18:21:10.270
Link: CVE-2026-44221
No data.
OpenCVE Enrichment
Updated: 2026-05-13T10:36:12Z
Github GHSA