{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/arcadedb-gremlin--26.7.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-75853"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["arcadedb-gremlin (\u003c= 26.7.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ArcadeDB"],"content_html":"\u003cp\u003eThe vulnerability (CVE-2026-75853) affects the arcadedb-gremlin plugin used by ArcadeDB versions 26.7.3 and earlier. While the plugin correctly implements SASL PLAIN authentication, it fails to enforce authorization logic. Specifically, the plugin does not invoke the check for database access permissions (canAccessToDatabase) and fails to bind the authenticated user to the database engine. Consequently, any user with valid server credentials can read, write, or drop data across any database hosted on the server. This bypasses all engine-level security controls, including per-type ACLs, read-only constraints, and schema update restrictions. The issue was resolved in version 26.8.1. Organizations running ArcadeDB with the Gremlin plugin enabled should prioritize upgrading to 26.8.1 to restore granular database access controls.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the target ArcadeDB server using valid (potentially low-privileged) credentials via the Gremlin wire-protocol.\u003c/li\u003e\n\u003cli\u003eAttacker establishes a session using the SASL PLAIN authentication mechanism.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a target database on the server, potentially one they are not authorized to access.\u003c/li\u003e\n\u003cli\u003eAttacker uses a traversal-source alias to reference the unauthorized target database within the Gremlin query structure.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the request without performing an authorization check against the database engine.\u003c/li\u003e\n\u003cli\u003eThe underlying engine executes the request with the context of the authenticated session, ignoring the intended ACL boundaries.\u003c/li\u003e\n\u003cli\u003eAttacker performs unauthorized actions such as data exfiltration (read), modification (write), or data destruction (drop).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to bypass all database-level security restrictions. An attacker can gain unauthorized read/write/delete access to any database hosted on an instance where they possess valid credentials for at least one database. This impacts data confidentiality, integrity, and availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the arcadedb-gremlin plugin to version 26.8.1 or later.\u003c/li\u003e\n\u003cli\u003eAudit database access logs for unusual cross-database traversals or queries initiated by accounts that should not have scope over the entire server.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege by restricting user credentials to the minimum necessary databases until patches are deployed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T14:54:20Z","date_published":"2026-08-18T14:54:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-arcadedb-auth-bypass/","summary":"The ArcadeDB Gremlin wire-protocol plugin versions 26.7.3 and prior fail to perform authorization checks for authenticated users, allowing unauthorized cross-database data manipulation and ACL bypass.","title":"Authorization Bypass in ArcadeDB Gremlin Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-arcadedb-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Arcadedb-Gremlin (\u003c= 26.7.3)","version":"https://jsonfeed.org/version/1.1"}