Junglewise Threat Intelligence

CVE-2026-75850: ArcadeDB authentication bypass in batch/time-series HTTP handlers

CVE-2026-75850 · Severity: medium · CVSS 4.2 · Published 2026-08-18

Technologies: ArcadeData ArcadeDB. Vendors: ArcadeData.

Executive brief

ArcadeDB is a multi-model database used to store and query structured data. The batch and time-series HTTP endpoints fail to properly authenticate user access restrictions, allowing a limited user to read and write data types they should not have permission to access. This only affects deployments using fine-grained per-type access controls; simpler database-level access control configurations are not impacted.

Technical details

The vulnerability is a missing authorization enforcement (CWE-862) in ArcadeDB's batch and time-series HTTP request handlers. The root cause is that while checkAuthorizationOnDatabase validates coarse database-level access, it does not bind the authenticated principal (setCurrentUser) on the worker thread. As a result, the engine's fine-grained per-type ACL layer (LocalBucket.checkPermissionsOnFile) cannot execute and returns early when the bound user is null, allowing per-type authorization checks to be bypassed. An authenticated attacker with database access but restricted per-type permissions can submit requests to /api/v1/batch or time-series endpoints to read from or write to types they are not authorized to access. The vulnerability requires low privileges (valid database user) and high attack complexity (knowledge of type names and API structure) but has no network complexity barriers. Patches are available in ArcadeDB 26.8.1 and later.

Affected products

  • ArcadeData ArcadeDB before 26.8.1

Timeline

  • 2026-08-04: disclosed: GitHub security advisory GHSA-c23x-pqcj-7hfm published
  • 2026-08-18: advisory: CVE-2026-75850 published
  • 2026-08-18: patched: Patch available in ArcadeDB 26.8.1

References

Related threats