Arcadedata Arcadedb vulnerabilities
33 known vulnerabilities affecting arcadedata/arcadedb.
Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH19MEDIUM7
Vulnerabilities
Page 2 of 2
CVE-2026-93598P3HIGHCVSS 7.1fixed in 26.9.12026-09-18
CVE-2026-93598 [HIGH] CWE-184 CVE-2026-93598: ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-li
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare class name, which is matched by exact equality and therefore does not cover its subclasses, while ScriptTriggerExecutor.
nvd
CVE-2026-93597P3HIGHCVSS 7.7fixed in 26.9.12026-09-18
CVE-2026-93597 [HIGH] CWE-918 CVE-2026-93597: ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by
ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or loopback IPv4 payloads to reach internal services and cloud metadata endpoints.
nvd
CVE-2026-76225P3HIGHCVSS 7.7fixed in 26.8.12026-08-19
CVE-2026-76225 [HIGH] CWE-918 CVE-2026-76225: ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD C
ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft LOAD CSV queries pointing to internal network addresses or cloud metadata endpoints to make the ArcadeDB server fetch and return sensitive data from restricted s
nvd
CVE-2026-54077P3HIGHCVSS 7.1fixed in 26.6.12026-09-15
CVE-2026-54077 [HIGH] CWE-22 CVE-2026-54077: ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/ja
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java without validation. An authenticated user wi
nvd
CVE-2026-75846P3HIGHCVSS 7.1fixed in 26.8.12026-08-18
CVE-2026-75846 [HIGH] CWE-862 CVE-2026-75846: ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability
ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a server-side function without any checkPermissionsOnDatabase (UPDATE_SCHEMA) check. Any user with database access can execute DELETE FUNCTIO
nvd
CVE-2026-75845P3MEDIUMCVSS 6.3≥ 26.4.2, < 26.8.12026-08-18
CVE-2026-75845 [MEDIUM] CWE-269 CVE-2026-75845: ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_ser
ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSettingTool.execute() gates only on the global allowAdmin flag and never checks the caller's role, so in an MCP deployment with allowAdmin=true and a non-root allowedUsers set, any authenticated read-only us
nvd
CVE-2026-76223P3HIGHCVSS 7.1fixed in 26.8.12026-08-19
CVE-2026-76223 [HIGH] CWE-862 CVE-2026-76223: ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission che
ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION statement targets an already-existing function library. A user with only database access can add or overwrite SQL or Cypher functions in an existing library and persist the change, enabling tampering with admin-defined function
nvd
CVE-2026-93595P3MEDIUMCVSS 6.5fixed in 26.9.12026-09-18
CVE-2026-93595 [MEDIUM] CWE-862 CVE-2026-93595: ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool ex
ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints. The tool executes queries without binding the authenticated principal to DatabaseContext, causing per-type and per-bucket ACL checks to silently no-op and allowing authenticated users to read data they are explicit
nvd
CVE-2026-75839P4MEDIUMCVSS 4.3fixed in 26.8.12026-08-18
CVE-2026-75839 [MEDIUM] CWE-200 CVE-2026-75839: ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object referen
ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object reference (IDOR) vulnerability in the Raft cluster-info endpoints (GetClusterHandler and PostBootstrapStateHandler), which authenticate but do not authorize access. On an ArcadeDB HA cluster (only reachable when arcadedb.ha.enabled is set and the ha-raft mod
nvd
CVE-2026-67344P4MEDIUMCVSS 4.3fixed in 26.7.22026-08-01
CVE-2026-67344 [MEDIUM] CWE-862 CVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ...
ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocumentType. An authenticated user with only read access (e.g., a read-only API token) can submit these ALTER TYPE sta
nvd
CVE-2026-75850P4MEDIUMCVSS 4.2fixed in 26.8.12026-08-18
CVE-2026-75850 [MEDIUM] CWE-862 CVE-2026-75850: ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and t
ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers. Because no principal is bound on the worker thread, the engine's fine-grained per-type ACL layer (LocalBucket.checkPermissionsOnFile) does not execute for these handlers. In deployments that use per-type or per-group ACLs, a
nvd
CVE-2026-93596P4MEDIUMCVSS 4.3fixed in 26.9.12026-09-18
CVE-2026-93596 [MEDIUM] CWE-862 CVE-2026-93596: ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated prin
ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine _out_edges/_in_edges buckets, resulting in unauthorized modification of graph adjacency. Setting parallelFlush=false causes the request to be correctly rejected. This is an incomplete fix of GHSA-c23x-pqcj-7hfm, which bound the principal only on the HTTP handler thread.
nvd
CVE-2026-75841P4MEDIUMCVSS 4.3fixed in 26.8.12026-08-18
CVE-2026-75841 [MEDIUM] CWE-770 CVE-2026-75841: ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function tha
ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary service degradation or unavailability.
nvd
← Previous2 / 2