A vulnerability was found in ArcadeData ArcadeDB up to 26.7.2 and classified as critical. This affects the function getSecurity.createUser of the component JavaScript Trigger Context. Executing a manipulation can lead to improper privilege management.

The identification of this vulnerability is CVE-2026-67356. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.