CVE-2026-67356
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Aug 02, 2026
Vendor
unknown
Description
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.