THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67344 (MEDIUM 4.3) — ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocumentType. An authenticated user with only r

[NVD] CVE-2026-67344 (MEDIUM 4.3) — ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocumentType. An authenticated user with only r

mednvdPublished 2026-08-01

CVE-2026-67344 CVSS: 4.3 MEDIUM Published: 2026-08-01T13:17:05.700

ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocumentType. An authenticated user with only read access (e.g., a read-only API token) can submit

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67344