THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67342 (CRITICAL 9.8) — ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by

[NVD] CVE-2026-67342 (CRITICAL 9.8) — ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by

mednvdPublished 2026-08-01

CVE-2026-67342 CVSS: 9.8 CRITICAL Published: 2026-08-01T13:17:05.417

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67342