{"id":"CVE-2026-93594","published":"2026-09-18T14:19:10.587","lastModified":"2026-09-18T15:17:21.587","description":"ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or the TimeSeries engine never invoke that permission check, so an authenticated user who is denied readRecord/deleteRecord on a type can still, with a single ordinary SQL statement, read the type's indexed key values and record IDs (e.g. SELECT key, rid FROM INDEX:Type[field]), read MAX/MIN values via the index shortcut, read and count TimeSeries samples, learn the type's record count, and delete index entries (DELETE FROM INDEX:Type[field]), which desynchronizes the index from the data and can defeat unique constraints. Index and type names needed for exploitation are discoverable because SELECT FROM schema:indexes is unfiltered. The issue affects both embedded and server deployments and all transports (HTTP, Bolt, Postgres, Gremlin) once a principal is bound. Fixed in 26.9.1.","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-2c8m-q484-jv7m","tags":[]},{"url":"https://www.vulncheck.com/advisories/arcadedb-before-26.9.1-acl-bypass-via-index-and-timeseries","tags":[]},{"url":"https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-2c8m-q484-jv7m","tags":[]}],"exploitRefs":[{"url":"https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-2c8m-q484-jv7m","tags":[]},{"url":"https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-2c8m-q484-jv7m","tags":[]}],"hasPoc":true,"ai":null}