- CVE ID
- CVE-2026-67356
- CVE Description
- ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.
- Published
- Aug 3, 2026
- CVSS Score & Severity
8.8High
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS Score
- 0.442%
- KEV Status
Not in KEV Catalog: No known exploits
- Source
- National Vulnerability Database