CVE-2026-93593: ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission

Published Sep 18, 2026
·
Updated

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privilege user can read or insert TimeSeries samples despite explicit deny rules by exploiting the missing type-name-based access check that causes permission lookups to fail open.

Affected Software

1 affected component
ArcadeDB<26.9.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ArcadeDB TimeSeries ACL bypass (missing type-name-based access check) to a version that resolves this vulnerability.

    Fixed in 26.9.1

Event History

Sep 18, 2026
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated low-privilege ArcadeDB user can exploit it. The attacker needs access to a TimeSeries type for which security-group type ACL entries include explicit deny rules.

2

Are TimeSeries deployments affected by default?

The issue concerns deployments that rely on security-group type ACL entries to deny access to TimeSeries types. The provided information does not establish whether any default configuration includes such deny rules.

3

What access can an attacker gain?

An attacker can read TimeSeries samples or insert new samples despite explicit deny rules. The supplied data does not indicate that deletion or modification of existing samples is possible.

4

How can I determine whether my deployment is affected?

Check whether ArcadeDB is before 26.9.1 and whether TimeSeries types are protected using security-group type ACL deny entries. Affected configurations may allow a low-privilege authenticated account to read from or insert into those TimeSeries types despite the configured denial.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203