cbcvebase.

Arcadedata Arcadedb vulnerabilities

33 known vulnerabilities affecting arcadedata/arcadedb.

Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH19MEDIUM7

Vulnerabilities

Page 1 of 2
CVE-2026-75854P2CRITICALCVSS 9.8fixed in 26.8.12026-08-18
CVE-2026-75854 [CRITICAL] CWE-306 CVE-2026-75854: ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-pro ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on the server without providing credentials, bypassing all security gates
nvd
CVE-2026-75852P2CRITICALCVSS 9.8fixed in 26.8.12026-08-18
CVE-2026-75852 [CRITICAL] CWE-306 CVE-2026-75852: ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
nvd
CVE-2026-75851P2CRITICALCVSS 9.9fixed in 26.8.12026-08-18
CVE-2026-75851 [CRITICAL] CWE-269 CVE-2026-75851: ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext has no bound user, causing the scripting authorization gate to become a
nvd
CVE-2026-76224P2HIGHCVSS 8.8fixed in 26.8.12026-08-19
CVE-2026-76224 [HIGH] CWE-94 CVE-2026-76224: ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulne ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure java (gremlin-lang) engine, ArcadeGremlin.executeStatement() silently falls back to the insecure Groovy engine whenever a request carries any query parameter and
nvd
CVE-2026-67342P2CRITICALCVSS 9.8fixed in 26.7.22026-08-01
CVE-2026-67342 [CRITICAL] CWE-639 CVE-2026-67342: ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for t ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary database parameter
nvd
CVE-2026-75843P2CRITICALCVSS 9.9fixed in 26.8.12026-08-18
CVE-2026-75843 [CRITICAL] CWE-269 CVE-2026-75843: ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor th ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a transaction ID to run unrestricted JavaScript that creates server-wide admini
nvd
CVE-2026-75853P2HIGHCVSS 8.8fixed in 26.8.12026-08-18
CVE-2026-75853 [HIGH] CWE-862 CVE-2026-75853: ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforc ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds the authenticated principal into the engine. As a result, any valid server credential — even one provisioned
nvd
CVE-2026-67341P3CRITICALCVSS 9.8fixed in 26.7.22026-08-01
CVE-2026-67341 [CRITICAL] CWE-863 CVE-2026-67341: ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUN ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.
nvd
CVE-2026-75855P3HIGHCVSS 8.7fixed in 26.8.12026-08-18
CVE-2026-75855 [HIGH] CWE-22 CVE-2026-75855: ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint' ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configured database directory. Attackers can supply database names containing ../ sequences to create databases at arbitrary f
nvd
CVE-2026-67343P3HIGHCVSS 8.8fixed in 26.7.22026-08-01
CVE-2026-67343 [HIGH] CWE-200 CVE-2026-67343: ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and execute administrative acti
nvd
CVE-2026-67356P3HIGHCVSS 8.8fixed in 26.7.32026-08-02
CVE-2026-67356 [HIGH] CWE-269 CVE-2026-67356: ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with Hos ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their a
nvd
CVE-2026-44221P3CRITICALCVSS 9.0fixed in 26.7.12026-05-12
CVE-2026-44221 [CRITICAL] CWE-863 CVE-2026-44221: ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticat ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized
nvd
CVE-2026-93594P3HIGHCVSS 8.1fixed in 26.9.12026-09-18
CVE-2026-93594 [HIGH] CWE-863 CVE-2026-93594: ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-reco ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or the TimeSeries engine never invoke that permission check, so an authenticated user who is denied readRecord/deleteReco
nvd
CVE-2026-93593P3HIGHCVSS 8.1fixed in 26.9.12026-09-18
CVE-2026-93593 [HIGH] CWE-863 CVE-2026-93593: ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types becaus ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privilege user can read or insert TimeSeries samples despite explicit deny rules by exploiting the missing type-name-based
nvd
CVE-2026-75842P3HIGHCVSS 7.7fixed in 26.8.12026-08-18
CVE-2026-75842 [HIGH] CWE-22 CVE-2026-75842: ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in LOAD CSV statements to access arbitrary files with server process privileges, exfiltrating sensitive data directly in
nvd
CVE-2026-68578P3HIGHCVSS 7.5fixed in 26.7.32026-08-02
CVE-2026-68578 [HIGH] CWE-306 CVE-2026-68578: ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.
nvd
CVE-2026-75840P3HIGHCVSS 7.5fixed in 26.8.12026-08-18
CVE-2026-75840 [HIGH] CWE-1025 CVE-2026-75840: ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandb ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. Attackers with trigger creation privileges can use Java.type() to access java.util.zip.ZipFile or java.util.jar.JarFile classes and read arbitrary files on th
nvd
CVE-2026-67357P3HIGHCVSS 7.5fixed in 26.7.32026-08-02
CVE-2026-67357 [HIGH] CWE-200 CVE-2026-67357: ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_serve ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server com
nvd
CVE-2026-67340P3HIGHCVSS 7.2fixed in 26.7.22026-08-01
CVE-2026-67340 [HIGH] CWE-94 CVE-2026-67340: ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().exec() (or ProcessBuilder), achievi
nvd
CVE-2026-75844P3HIGHCVSS 7.1fixed in 26.8.12026-08-18
CVE-2026-75844 [HIGH] CWE-918 CVE-2026-75844: ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DA ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the subsequent connection re-resolves the raw URL and follows redirects. Authenticated attackers can bypass the validator using DNS rebinding or HTTP redirects to access cloud
nvd
Arcadedata Arcadedb vulnerabilities | cvebase