THREAT OPS › Threat News › [NVD] CVE-2026-67342 (CRITICAL 9.8) — ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by
[NVD] CVE-2026-67342 (CRITICAL 9.8) — ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by
CVE-2026-67342 CVSS: 9.8 CRITICAL Published: 2026-08-01T13:17:05.417
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary
Indicators of compromise
- CVE-2026-67342cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67342