CVE-2026-76223: ArcadeDB before 26.8.1 Permission Bypass via DEFINE FUNCTION

Published Aug 19, 2026
·
Updated

ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATESCHEMA permission check when a DEFINE FUNCTION statement targets an already-existing function library. A user with only database access can add or overwrite SQL or Cypher functions in an existing library and persist the change, enabling tampering with admin-defined function logic. The issue is fixed in 26.8.1. (JavaScript functions still trigger the UPDATESECURITY check and are not affected.)

Affected Software

1 affected component
ArcadeDB ArcadeDB<26.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ArcadeDB (com.arcadedb) to a version that resolves this vulnerability.

    Fixed in 26.8.1

Event History

Aug 19, 2026
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A user with database access can exploit it if they can issue a DEFINE FUNCTION statement against an existing function library. The vulnerable permission check is not enforced for that operation.

2

What function types are affected?

SQL and Cypher functions in an existing library can be added or overwritten. JavaScript functions are not affected because they still trigger the UPDATE_SECURITY permission check.

3

Which versions need remediation?

ArcadeDB 26.7.3 and earlier are affected. The issue is fixed in version 26.8.1.

4

How can I determine whether tampering may have occurred?

Review existing SQL and Cypher function libraries for functions that were added or modified by accounts that had database access but should not have had schema-update privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203