Vulnerability Description
ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION statement targets an already-existing function library. A user with only database access can add or overwrite SQL or Cypher functions in an existing library and persist the change, enabling tampering with admin-defined function logic. The issue is fixed in 26.8.1. (JavaScript functions still trigger the UPDATE_SECURITY check and are not affected.)
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-rv64-62hr-wv2p
- https://www.vulncheck.com/advisories/arcadedb-before-permission-bypass-via-defin
FAQ
What is CVE-2026-76223?
CVE-2026-76223 is a vulnerability with a CVSS score of 7.1 (HIGH). ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION statement targets an already-existing function library. A user with only d...
How severe is CVE-2026-76223?
CVE-2026-76223 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-76223?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.