


Perceptive Security
SOC/SIEM Consultancy

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().cr…
Published:
1 August 2026 at 22:00:00
Alert date:
2 August 2026 at 14:02:48
Source:
nvd.nist.gov
Database & Storage, Identity & Access, Zero-Day Vulnerabilities
ArcadeDB versions before 26.7.3 contain a critical privilege escalation vulnerability where the real LocalDatabase object is bound into JavaScript trigger contexts with HostAccess.ALL. This misconfiguration allows users with UPDATE_SCHEMA permission to craft JavaScript triggers that invoke getSecurity().createUser() without any permission checks. As a result, schema-admins can create server-wide administrative users, escalating their privileges far beyond their authorized level. The vulnerability is exploitable by any attacker who has obtained UPDATE_SCHEMA permissions on the database. A fix is available in ArcadeDB version 26.7.3 and later. The issue has been documented in a GitHub security advisory and tracked by VulnCheck.
Technical details
Mitigation steps:
Affected products:
ArcadeDB
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67356
https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-38pf-6hp2-pxww
https://www.vulncheck.com/advisories/arcadedb-before-privilege-escalation-via-javascript-trigger
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
