


Perceptive Security
SOC/SIEM Consultancy

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fa…
Published:
31 juli 2026 om 22:00:00
Alert date:
1 augustus 2026 om 14:10:40
Source:
nvd.nist.gov
Database & Storage, Web Technologies, Identity & Access
ArcadeDB versions prior to 26.7.2 contain an authorization bypass vulnerability affecting HTTP handlers for time series, batch, Prometheus, and Grafana endpoints. These endpoints fail to validate database access permissions, allowing unauthenticated or unauthorized attackers to access and modify databases by directly calling the affected endpoints with arbitrary database parameters. The vulnerability enables both unauthorized data access and data modification, posing a significant risk to confidentiality and integrity. A fix is available in ArcadeDB version 26.7.2 and later. The issue has been documented by NVD, GitHub Security Advisories, and VulnCheck.
Technical details
Mitigation steps:
Affected products:
ArcadeDB
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67342
https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-x8mg-6r4p-87pf
https://www.vulncheck.com/advisories/arcadedb-before-authorization-bypass-via-database-handlers
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
