MEDIUMCVSS 5.3
CVE-2026-93596
CVE-2026-93596 updated by NVD
Summary
ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine _out_edges/ _in_edges buckets, resulting in unauthorized modification of graph adjacency. Setting parallelFlush=false causes the request to be correctly rejected. This is an incomplete fix of GHSA-c23x-pqcj-7hfm, which bound the principal only on the HTTP handler thread.
References
Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.