CVE-2026-67341: Incorrect Authorization in ArcadeData arcadedb
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.
AI Analysis
Technical Summary
CVE-2026-67341 is an incorrect authorization vulnerability in ArcadeDB affecting versions before 26.7.2. The issue arises because the database fails to enforce proper authorization checks on the SQL DEFINE FUNCTION statement when the LANGUAGE is set to js (JavaScript). As a result, any user with database access can define functions containing arbitrary JavaScript code, bypassing security controls designed to restrict scripting capabilities to administrative users only. This vulnerability has a CVSS 4.0 base score of 9.3, indicating critical severity with network attack vector, no privileges required, and no user interaction needed.
Potential Impact
An attacker with access to the database can execute arbitrary JavaScript code by submitting specially crafted DEFINE FUNCTION statements. This bypasses the intended security controls that restrict scripting to administrators, potentially leading to unauthorized code execution within the database environment. The vulnerability does not require prior privileges or user interaction, increasing its risk profile.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict database access to trusted users only and monitor for unauthorized DEFINE FUNCTION statements. Avoid granting unnecessary database access privileges to untrusted users.
CVE-2026-67341: Incorrect Authorization in ArcadeData arcadedb
Description
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.
CVSS v4.0
Score 9.3critical
Affected software
ArcadeData
arcadedb
pkg:github/arcadedata/arcadedbRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-67341 is an incorrect authorization vulnerability in ArcadeDB affecting versions before 26.7.2. The issue arises because the database fails to enforce proper authorization checks on the SQL DEFINE FUNCTION statement when the LANGUAGE is set to js (JavaScript). As a result, any user with database access can define functions containing arbitrary JavaScript code, bypassing security controls designed to restrict scripting capabilities to administrative users only. This vulnerability has a CVSS 4.0 base score of 9.3, indicating critical severity with network attack vector, no privileges required, and no user interaction needed.
Potential Impact
An attacker with access to the database can execute arbitrary JavaScript code by submitting specially crafted DEFINE FUNCTION statements. This bypasses the intended security controls that restrict scripting to administrators, potentially leading to unauthorized code execution within the database environment. The vulnerability does not require prior privileges or user interaction, increasing its risk profile.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict database access to trusted users only and monitor for unauthorized DEFINE FUNCTION statements. Avoid granting unnecessary database access privileges to untrusted users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-29T13:09:45.992Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6deb27bf32cb7a34c1fc4a
Added to database: 08/01/2026, 12:48:39 UTC
Last enriched: 08/08/2026, 14:24:46 UTC
Last updated: 09/12/2026, 22:01:36 UTC
Views: 107
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.