Junglewise Threat Intelligence

CVE-2026-44221: ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a spec

CVE-2026-44221 · Severity: critical · CVSS 9 · Published 2026-05-12

Technologies: com.arcadedb:arcadedb-server (Maven), ArcadeData Arcadedb-Server. Vendors: Maven, ArcadeData.

Executive brief

ArcadeDB is a multi-model database engine. A security flaw allows any user with access to one database to bypass security checks and read, modify, or delete data in any other database on the same server. This could lead to unauthorized access to sensitive information or complete data loss across the entire database environment.

Technical details

ArcadeDB contains two defects that lead to an authorization bypass. First, 'ServerSecurityUser.getDatabaseUser()' returns a user object with an uninitialized 'fileAccessMap', which the 'requestAccessOnFile' method incorrectly interprets as granting full access. Second, the 'ArcadeDBServer.createDatabase()' method fails to initialize security settings for databases created via the API, resulting in record-level authorization being disabled by default. An attacker with low-privileged network access can exploit these flaws to perform cross-database CRUD operations and schema mutations. The vulnerability is addressed in version 26.4.2.

Affected products

  • ArcadeData arcadedb-server >= 21.10.1, < 26.4.2

Timeline

  • 2026-04-27: disclosed: Initial report by sealbenb
  • 2026-05-05: advisory: GitHub Advisory published
  • 2026-05-12: other: NVD publication date

References

Related threats