medium · CVSS v3 4.3 · CVSS v4 5.3
CVE-2026-93596
ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine _out_edges/ _in_edges buckets, resulting in unauthorized modificati…
Description
ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine _out_edges/ _in_edges buckets, resulting in unauthorized modification of graph adjacency. Setting parallelFlush=false causes the request to be correctly rejected. This is an incomplete fix of GHSA-c23x-pqcj-7hfm, which bound the principal only on the HTTP handler thread.
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 4.3
- CVSS v4
- 5.3
- EPSS
- —