VYPR
Unrated severityNVD Advisory· Published Aug 1, 2026· Updated Aug 3, 2026

ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION

CVE-2026-67341

Description

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.