Skip to content
Threat Feed

Vendor

ArcadeData

6 briefs RSS
high advisory

SSRF Vulnerability in ArcadeDB via IPv6 Transition Addressing

Authenticated attackers can exploit a validation flaw in ArcadeDB's SSRF guard to reach internal services or cloud metadata endpoints by using specifically crafted IPv6 transition addresses.

ArcadeDB ssrf vulnerability database access-control
2t 1c
critical advisory

Authentication Bypass and Privilege Escalation in ArcadeDB

ArcadeDB versions before 26.8.1 contain a vulnerability in the gRPC transaction executor that allows authenticated readers to execute arbitrary JavaScript, leading to server-wide privilege escalation.

ArcadeDB privilege-escalation database-security cve-2026-75843 vulnerability authentication-bypass arbitrary-file-read sandbox-bypass cve-2026-75840 +3
1r 5t 1c
high advisory

ArcadeDB Privilege Escalation via JavaScript Triggers

ArcadeDB versions before 26.7.3 insecurely expose the LocalDatabase object to JavaScript triggers, allowing attackers with schema update permissions to perform unauthorized administrative actions.

ArcadeDB +1 information-disclosure privilege-escalation database authentication-bypass database-security cve-2026-68578
1r 3t 1c
critical advisory

Remote Code Execution in ArcadeDB via Script Triggers

An authenticated remote code execution vulnerability (CVE-2026-67340) in ArcadeDB engine versions before 26.7.2 allows attackers to escape script sandboxing and execute arbitrary OS commands.

PoC arcadedb-engine +1 cve-2026-67340 rce database arcadedb
1t 1c 1i updated
high advisory

ArcadeDB IMPORT DATABASE Allows SSRF and Arbitrary Local File Read

Authenticated users can exploit an unvalidated `IMPORT DATABASE` function in ArcadeDB (CVE-2026-54077) to perform Server-Side Request Forgery (CWE-918) against cloud metadata endpoints and internal services, or achieve arbitrary local file read (CWE-22) via `file://` paths, exposing sensitive data.

arcadedb-engine arcadedb ssrf file-read cve database
2r 3t
critical advisory

ArcadeDB Authorization Bypass Vulnerability

ArcadeDB versions prior to 26.4.2 are vulnerable to an authorization bypass, allowing authenticated users and API tokens scoped to a specific database to read, write, and mutate schema on any other database on the same server, and disabling the record-level authorization system for newly created databases.

arcadedb-server +2 authorization bypass privilege escalation cve-2026-44221
2r 2t 1c updated