CVE-2026-54077
published 2026-09-15CVE-2026-54077: ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.jav…
PriorityP345high7.1CVSS 3.1
AVNACLPRLUINSUCHINAL
EPSS
0.37%
31.3th percentile
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java without validation. An authenticated user with SQL command access through /api/v1/command or /api/v1/query can supply HTTP or HTTPS destinations to make server-side requests to internal services, or file:// paths to read files accessible to the server process and ingest the results as queryable records. The XML importer also permits DTD processing and external entities, enabling entity expansion. The root-only /api/v1/server administration endpoint is not affected. The fix requires updateSecurity permission, blocks local-network import destinations by default through arcadedb.server.security.importBlockLocalNetworks, supports the arcadedb.server.security.importAllowedLocalPaths file allow-list, and disables XML DTD processing and external entities. This issue is fixed in version 26.6.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arcadedata | arcadedb | < 26.6.1 | 26.6.1 |
| com.arcadedb | arcadedb-engine | < 26.6.1 | 26.6.1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
ghsa9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
ghsa·2026-07-16·CVSS 9.0
CVE-2026-44221 [CRITICAL] CWE-269 ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
### Impact
A user holding only `reader` (read-only) privileges on a single database could execute arbitrary JVM code by sending a `"language": "js"` command to the `POST /api/v1/command/{database}` HTTP endpoint, and use it to read arbitrary files on the host filesystem (e.g. `/etc/passwd`, configuration files), outside the scope of the database itself.
Two cooperating defects made this possible:
1. **Missing authorization on the scripting path (CWE-863 / CWE-269).** Polyglot script execution (`js` and other GraalVM languages) never went through the database authorization checks applied to SQL/Cypher, so any authenticated principal - regardless of database role - could run
GHSA
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
ghsa·2026-07-16
CVE-2026-54077 [HIGH] CWE-22 ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
### Impact
The SQL `IMPORT DATABASE` statement did not require administrative privileges and passed its source URL to the importer without validation. Any authenticated user with SQL command access (not only `root`/administrators) could therefore:
- **Server-Side Request Forgery (CWE-918):** cause the server to issue HTTP(S) requests to arbitrary destinations, including cloud metadata endpoints (e.g. `169.254.169.254`) and internal-only services, and ingest the responses as queryable records.
- **Arbitrary local file read (CWE-22):** read local files reachable by the server process (e.g. `/etc/passwd`, credential files) by importing `file://` paths, exposing their contents as records.
The server
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-15
Published