CVE-2026-44221 | ArcadeData arcadedb up to 2.6.3 ServerSecurityUser.getDatabaseUser authorization (GHSA-fxc7-fm93-6q77)
A vulnerability was found in ArcadeData arcadedb up to 2.6.3. It has been rated as critical. The affected element is the function ServerSecurityUser.getDatabaseUser. This manipulation causes incorrect authorization.
This vulnerability is handled as CVE-2026-44221. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.