{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-67340/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-67340"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["arcadedb-engine"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-67340","rce","database","arcadedb"],"_cs_type":"advisory","_cs_vendors":["ArcadeData"],"content_html":"\u003cp\u003eArcadeDB versions prior to 26.7.2 are vulnerable to remote code execution due to a flaw in the \u003ccode\u003eScriptTriggerExecutor\u003c/code\u003e component. The vulnerability arises because the engine permits trigger scripts to access host classes within the \u003ccode\u003ejava.lang.*\u003c/code\u003e package via the \u003ccode\u003eJava.type\u003c/code\u003e object. Because these packages are explicitly added to the allowed list, an authenticated user possessing the \u003ccode\u003eUPDATE_SCHEMA\u003c/code\u003e permission can register a malicious JavaScript trigger. This trigger can instantiate and invoke sensitive Java classes such as \u003ccode\u003ejava.lang.Runtime.getRuntime().exec()\u003c/code\u003e or \u003ccode\u003eProcessBuilder\u003c/code\u003e to execute arbitrary commands at the operating system level. This issue poses a critical risk to organizations utilizing ArcadeDB, as it allows for full compromise of the underlying server infrastructure by any user with standard schema-management privileges.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the ArcadeDB instance using valid, low-privileged credentials that include the \u003ccode\u003eUPDATE_SCHEMA\u003c/code\u003e permission.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the database schema management interface to initiate the creation of a new database trigger.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a payload using JavaScript that leverages the insecure \u003ccode\u003eJava.type\u003c/code\u003e object to gain access to the restricted \u003ccode\u003ejava.lang.Runtime\u003c/code\u003e class.\u003c/li\u003e\n\u003cli\u003eAttacker defines the trigger script, embedding the Java runtime command execution logic within the trigger definition.\u003c/li\u003e\n\u003cli\u003eThe ArcadeDB server registers the malicious JavaScript code within the \u003ccode\u003eScriptTriggerExecutor\u003c/code\u003e engine.\u003c/li\u003e\n\u003cli\u003eThe trigger event occurs (e.g., an insert, update, or delete operation on the target collection), causing the \u003ccode\u003eScriptTriggerExecutor\u003c/code\u003e to evaluate the script.\u003c/li\u003e\n\u003cli\u003eThe Java Virtual Machine executes the malicious OS commands with the privileges of the ArcadeDB process.\u003c/li\u003e\n\u003cli\u003eFinal objective achieved: full code execution and potential persistence or system exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-67340 leads to complete remote code execution on the server hosting the ArcadeDB instance. Given the critical severity (CVSS 9.8), an attacker gaining this level of access can exfiltrate sensitive database contents, modify records, or pivot into the internal network. The scope of impact is limited to environments where attackers have obtained authenticated access to the database with schema modification capabilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003earcadedb-engine\u003c/code\u003e component to version 26.7.2 or later immediately to address the insecure sandboxing configuration.\u003c/li\u003e\n\u003cli\u003eAudit all existing database triggers for unauthorized scripts or suspicious use of \u003ccode\u003eJava.type\u003c/code\u003e references.\u003c/li\u003e\n\u003cli\u003eRestrict the \u003ccode\u003eUPDATE_SCHEMA\u003c/code\u003e permission to the smallest number of administrative accounts necessary to limit the potential attack surface.\u003c/li\u003e\n\u003cli\u003eMonitor database administrative logs for unexpected calls to trigger creation or modification commands originating from non-administrative service accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T13:51:11Z","date_published":"2026-08-01T13:51:11Z","id":"https://feed.craftedsignal.io/briefs/2026-08-arcadedb-rce/","summary":"An authenticated remote code execution vulnerability (CVE-2026-67340) in ArcadeDB engine versions before 26.7.2 allows attackers to escape script sandboxing and execute arbitrary OS commands.","title":"Remote Code Execution in ArcadeDB via Script Triggers","url":"https://feed.craftedsignal.io/briefs/2026-08-arcadedb-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-67340","version":"https://jsonfeed.org/version/1.1"}