PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75846 ArcadeData CVE debrief

A missing authorization vulnerability in ArcadeDB before 26.8.1 allows any user with database access to permanently remove registered server-side functions via the command API, impacting integrity and availability. This vulnerability affects the DELETE FUNCTION SQL statement in ArcadeDB, allowing unauthorized deletion of server-side functions. The impact includes potential permanent removal of security-relevant server-side functions, integrity and availability impacts due to unauthorized function deletions, and the need for verification of affected versions and remediation status.

Vendor
ArcadeData
Product
arcadedb
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-08
Advisory published
2026-08-18
Advisory updated
2026-09-08

Who should care

Defenders and administrators of ArcadeDB instances should assess exposure and prioritize remediation to prevent potential integrity and availability impacts. This includes verifying affected versions, assessing exposure, and prioritizing remediation. Security teams and vulnerability management teams should also review the vulnerability and implement necessary mitigations.

Why it matters

CVE-2026-75846 is a high-severity vulnerability in ArcadeDB that allows unauthorized deletion of server-side functions, impacting integrity and availability. Defenders should prioritize verification, upgrading, and restricting database access.

  • Potential permanent removal of security-relevant server-side functions
  • Integrity and availability impacts due to unauthorized function deletions
  • Need for verification of affected versions and remediation status
  • Potential for lateral movement or privilege escalation if exploited

Technical summary

The DELETE FUNCTION SQL statement in ArcadeDB before 26.8.1 lacks authorization checks, allowing any user with database access to execute DELETE FUNCTION via the command API and permanently remove registered server-side functions. This vulnerability impacts integrity and availability, and defenders should prioritize verification, upgrading, and restricting database access to trusted users. The vulnerability affects the ArcadeDB database management system, specifically versions prior to 26.8.1, and allows unauthorized deletion of server-side functions.

Defensive priority

Defenders should prioritize verifying and upgrading to ArcadeDB version 26.8.1 or later, and restrict database access to trusted users.

Recommended defensive actions

  • Verify and upgrade to ArcadeDB version 26.8.1 or later
  • Restrict database access to trusted users
  • Monitor for unauthorized function deletions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but its scope and remediation require verification from official sources. The vulnerability was reported and verified through official channels, and its details were sourced from the CVE Program and NVD. However, defenders should verify the affected versions, assess exposure, and prioritize remediation to prevent potential integrity and availability impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75846 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75846

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75846 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75846

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.