CVE-2026-67344

Summary

ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE … CUSTOM and ALTER TYPE … BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocumentType. An authenticated user with only read access (e.g., a read-only API token) can submit these ALTER TYPE statements via the HTTP command endpoint to mutate a type's custom schema metadata and bucket-selection strategy, bypassing the documented updateSchema permission boundary and potentially corrupting schema metadata and record routing.

Affected Software

VendorProductVersion RangeStatus
ArcadeDataarcadedb0 < 26.7.2affected
ArcadeDataarcadedb26.7.2unaffected

Weaknesses

  • CWE-862: Missing Authorization

References