{"apiVersion":"1.0","identifier":"CVE-2026-76223","description":"ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION statement targets an already-existing function library. A user with only database access can add or overwrite SQL or Cypher functions in an existing library and persist the change, enabling tampering with admin-defined function logic. The issue is fixed in 26.8.1. (JavaScript functions still trigger the UPDATE_SECURITY check and are not affected.)","publishedAt":"2026-08-19T14:17:48","lastModifiedAt":"2026-08-19T15:18:10","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76223","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","epssProbability":0.00249,"riskScore":0.73,"affectedProduct":"ArcadeDB","affectedVersions":"<=26.7.3","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-76223","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-76223","en":"https://www.redsauce.net/en/cves/CVE-2026-76223","fr":"https://www.redsauce.net/fr/cves/CVE-2026-76223","pt":"https://www.redsauce.net/pt/cves/CVE-2026-76223","de":"https://www.redsauce.net/de/cves/CVE-2026-76223","sk":"https://www.redsauce.net/sk/cves/CVE-2026-76223","el":"https://www.redsauce.net/el/cves/CVE-2026-76223"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-76223"}}