VYPR

Arcadedb

by Arcadedata

Source repositories

CVEs (24)

  • CVE-2026-93596MedSep 18, 2026
    risk 0.21cvss 4.3epss

    ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}. Because those workers have no current user,…

  • CVE-2026-75841MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary…

  • CVE-2026-67344MedAug 1, 2026
    risk 0.21cvss 4.3epss 0.00

    ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocumentType. An authenticated user with only…

  • CVE-2026-75850MedAug 18, 2026
    risk 0.20cvss 4.2epss 0.00

    ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers. Because no principal is bound on the worker thread, the engine's fine-grained per-type ACL layer (LocalBucket.checkPermissionsOnFile) does not execute…

Page 2 of 2