ArcadeDB Cross-Database Authorization Bypass Vulnerability

Vulnerability

A vulnerability in ArcadeDB prior to version 2.6.4 allows authenticated users and API tokens scoped to a specific database to read, write, and modify the schema of any other database on the same server. This issue arises from two defects: first, the 'ServerSecurityUser.getDatabaseUser()' method returned a database user with an uninitialized file access map, which was interpreted as an allow-all permission. Second, the 'ArcadeDBServer.createDatabase()' method failed to initialize database security, leaving the record-level authorization system disabled for newly created databases. As a result, both record-level and database-level authorization could be bypassed by any authenticated user or token.

Impact

Exploitation of this vulnerability allows for a complete bypass of both record-level and database-level authorization, enabling unauthorized read, write, and schema modification actions across databases on the same server.

Reproduction

To reproduce this vulnerability, first create a database and a read-only API token scoped to that database. Then, use the token to attempt to insert data or modify the schema in a different database on the same server. The token should be able to perform these actions, demonstrating the cross-database authorization bypass.

Remediation

Users are advised to upgrade to ArcadeDB version 2.6.4, where this vulnerability has been fixed.

Added: May 12, 2026, 8:44 PM
Updated: May 12, 2026, 8:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.8
remediation
0.0
relevance
8.2
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.