A vulnerability labeled as critical has been found in ArcadeData ArcadeDB up to 26.7.1. The impacted element is the function setCustomValue/setBucketSelectionStrategy of the file LocalDocumentType of the component Alter Type Permission Enforcement. Such manipulation leads to improper privilege management.

This vulnerability is traded as CVE-2026-67344. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.