Executive brief
ArcadeDB is a graph/document database engine used to store and manage structured data. An authenticated user with only read-only access can bypass permission checks to modify database schema settings (custom metadata and record-routing strategy) through SQL statements, even though the documented permission model should restrict such changes to users with explicit update-schema rights. This allows low-privileged users to corrupt schema configuration and change how records are stored and retrieved.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations within ArcadeDB's schema layer. The setCustomValue() and setBucketSelectionStrategy() methods in LocalDocumentType.java do not enforce the UPDATE_SCHEMA database permission that is correctly applied to sibling schema-mutation operations. An authenticated user with read-only access can invoke these operations via the HTTP command endpoint (POST /api/v1/command/{database}) to mutate persisted schema metadata or change bucket-selection strategy, bypassing the documented updateSchema permission boundary. The vulnerability affects all released versions up to and including 26.7.1; a fix is available in version 26.7.2 and later.
Affected products
- ArcadeData ArcadeDB before 26.7.2
Timeline
- 2026-08-01: disclosed: Published on NVD and GitHub Security Advisory
- 2026-07-09: patched: Fix released in version 26.7.2