CRITICALMaven →
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
Affected packages
- com.arcadedb:arcadedb-server— 21.10.1 → 26.4.2
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.40%
- EPSS percentile
- 32.5%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 32%.
Sources
- https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-fxc7-fm93-6q77
- https://nvd.nist.gov/vuln/detail/CVE-2026-44221
- https://github.com/ArcadeData/arcadedb/commit/04110c06315da55604ac107f71fe7182f3a3deb8
- https://github.com/ArcadeData/arcadedb/commit/9e708f116b
- https://github.com/ArcadeData/arcadedb
Structured record: https://osv.dev/vulnerability/GHSA-fxc7-fm93-6q77
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta