CVE-2026-67342
ArcadeDB Authorization Bypass in HTTP Handlers Allows Unauthorized Database Access
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An authorization bypass vulnerability in ArcadeDB's HTTP handlers allows unauthenticated attackers to access and modify databases by directly calling affected endpoints. This impacts handlers for time series, batch, Prometheus, and Grafana endpoints. The issue is relevant when these endpoints are reachable, potentially