PatchSiren cyber security CVE debrief
CVE-2026-75846 ArcadeData CVE debrief
A missing authorization vulnerability in ArcadeDB before 26.8.1 allows any user with database access to permanently remove registered server-side functions via the command API, impacting integrity and availability. This vulnerability affects the DELETE FUNCTION SQL statement in ArcadeDB, allowing unauthorized deletion of server-side functions. The impact includes potential permanent removal of security-relevant server-side functions, integrity and availability impacts due to unauthorized function deletions, and the need for verification of affected versions and remediation status.
- Vendor
- ArcadeData
- Product
- arcadedb
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-08
Who should care
Defenders and administrators of ArcadeDB instances should assess exposure and prioritize remediation to prevent potential integrity and availability impacts. This includes verifying affected versions, assessing exposure, and prioritizing remediation. Security teams and vulnerability management teams should also review the vulnerability and implement necessary mitigations.
Why it matters
CVE-2026-75846 is a high-severity vulnerability in ArcadeDB that allows unauthorized deletion of server-side functions, impacting integrity and availability. Defenders should prioritize verification, upgrading, and restricting database access.
- Potential permanent removal of security-relevant server-side functions
- Integrity and availability impacts due to unauthorized function deletions
- Need for verification of affected versions and remediation status
- Potential for lateral movement or privilege escalation if exploited
Technical summary
The DELETE FUNCTION SQL statement in ArcadeDB before 26.8.1 lacks authorization checks, allowing any user with database access to execute DELETE FUNCTION via the command API and permanently remove registered server-side functions. This vulnerability impacts integrity and availability, and defenders should prioritize verification, upgrading, and restricting database access to trusted users. The vulnerability affects the ArcadeDB database management system, specifically versions prior to 26.8.1, and allows unauthorized deletion of server-side functions.
Defensive priority
Defenders should prioritize verifying and upgrading to ArcadeDB version 26.8.1 or later, and restrict database access to trusted users.
Recommended defensive actions
- Verify and upgrade to ArcadeDB version 26.8.1 or later
- Restrict database access to trusted users
- Monitor for unauthorized function deletions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but its scope and remediation require verification from official sources. The vulnerability was reported and verified through official channels, and its details were sourced from the CVE Program and NVD. However, defenders should verify the affected versions, assess exposure, and prioritize remediation to prevent potential integrity and availability impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75846 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75846
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75846 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75846
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-vv82-qvpf-rjwv
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/arcadedb-before-unauthorized-function-deletion-via-delete-function
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.