top of page
perceptive_background_267k.jpg

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fa…

Published:

31 juli 2026 om 22:00:00

Alert date:

1 augustus 2026 om 14:10:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Web Technologies, Identity & Access

ArcadeDB versions prior to 26.7.2 contain an authorization bypass vulnerability affecting HTTP handlers for time series, batch, Prometheus, and Grafana endpoints. These endpoints fail to validate database access permissions, allowing unauthenticated or unauthorized attackers to access and modify databases by directly calling the affected endpoints with arbitrary database parameters. The vulnerability enables both unauthorized data access and data modification, posing a significant risk to confidentiality and integrity. A fix is available in ArcadeDB version 26.7.2 and later. The issue has been documented by NVD, GitHub Security Advisories, and VulnCheck.

Technical details

Mitigation steps:

Affected products:

ArcadeDB

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page