A AegiFlow
MEDIUMCVSS 5.3

CVE-2026-93596

CVE-2026-93596 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine _out_edges/ _in_edges buckets, resulting in unauthorized modification of graph adjacency. Setting parallelFlush=false causes the request to be correctly rejected. This is an incomplete fix of GHSA-c23x-pqcj-7hfm, which bound the principal only on the HTTP handler thread.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.