Critical 9.0 CVSS Flaw in ArcadeDB Allows Total Cross-Database Access
ID: cfff6ca0-ce17-5f9d-aceb-432acbf4c45b
STIX ID: report--cfff6ca0-ce17-5f9d-aceb-432acbf4c45b
Feed Name: securityonline.info
ArcadeDB disclosed CVE-2026-44221 (CVSS 9.0): a critical authorization bypass caused by two architectural defects (an uninitialized fileAccessMap leading to allow-all behavior and a missing security initialization during database creation) that together permit authenticated users or tokens scoped to one database to read, write, or mutate schemas in any other database on the same server; the vendor released version 26.4.1 and recommends immediate upgrade as no workaround exists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
