Privilege Escalation Vulnerability in ArcadeDB via JavaScript Triggers (CVE-2026-67356)
A critical vulnerability (CVE-2026-67356) has been discovered in ArcadeDB, a popular database management system. The vulnerability has a CVSS score of 8.8 and allows attackers with UPDATE_SCHEMA permission to create triggers that execute JavaScript, leading to privilege escalation and potential creation of server-wide admin users. This vulnerability affects ArcadeDB versions before 26.7.3 and has not been actively exploited in the wild. Immediate patching or mitigation is recommended to prevent potential attacks.