CVE-2026-67341 Details
Description
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.
A vulnerability exists in ArcadeDB versions prior to 26.7.2, where the database fails to properly enforce authorization checks on the SQL DEFINE FUNCTION statement when using the JavaScript language. This oversight allows attackers with database access to execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, thereby circumventing security measures that restrict scripting capabilities to administrative users.
Users can upgrade to ArcadeDB version 26.7.2 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 1, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-vwjc-v7x7-cm6g | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/arcadedb-before-authorization-bypass-via-sql-define-function | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ArcadeDB | < 26.7.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2026 | New CVE Received | [email protected] |
Volerion