ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-02 13:16
Updated : 2026-08-31 20:30
NVD link : CVE-2026-67356
Mitre link : CVE-2026-67356
CVE.ORG link : CVE-2026-67356
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management
