Retour à la recherche

CVE-2026-67341

CRITICAL
9.8NVD

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.

Partager :

Score CVSS v3.1

9.8
/ 10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Informations

Publié
1 août 2026
Mis à jour
1 août 2026
Statut
Received
Source
disclosure@vulncheck.com

Faiblesses (CWE)

CWE-863

CVEs similaires

Autres vulnérabilités de type CWE-863

Loading…

Surveillez vos produits

Recevez une alerte automatique à chaque nouvelle CVE affectant vos équipements.

Activer la surveillance