📡 GitHub-Advisory · 2026-05-05
CVE-2026-44221 - ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-c
CVE-2026-44221
GHSA-fxc7-fm93-6q77 CRITICAL maven/com.arcadedb:arcadedb-server
CVE: CVE-2026-44221
Impact
Authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects