rootpwn

medium · CVSS v3 4.3 · CVSS v4 5.3

CVE-2026-93596

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine _out_edges/ _in_edges buckets, resulting in unauthorized modificati…

Description

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine _out_edges/ _in_edges buckets, resulting in unauthorized modification of graph adjacency. Setting parallelFlush=false causes the request to be correctly rejected. This is an incomplete fix of GHSA-c23x-pqcj-7hfm, which bound the principal only on the HTTP handler thread.

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
5.3
EPSS

← All CVEs