Threats Tagged 'cve-2026-75850'
View all threats tagged with 'cve-2026-75850'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-75850'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-75850: Missing Authorization in ArcadeData arcadedbCVE-2026-75850 0 ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers. Because no principal is bound on the worker thread, the engine's fine-grained per-type ACL layer (LocalBucket.checkPermissionsOnFile) does not execute for these handlers. In deployments that use per-type or per-group ACLs, a user with database access but only limited per-type permissions can read from and write to types they are not authorized to access by submitting requests to the batch/time-series endpoints. Deployments that rely solely on database-level access control are not affected. Join the discussion | CVE Database V5 | 08/18/2026, 11:19:54 UTC Added: 08/18/2026, 11:35:05 UTC |
Showing 1 to 1 of 1 result