Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-67356

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Aug 02, 2026
Vendor unknown

Description

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.

References