ArcadeData arcadedb
9 known vulnerabilities in ArcadeData arcadedb, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-93598 CVSS 7.1 high ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox…
- CVE-2026-93597 CVSS 5.3 medium ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands…
- CVE-2026-93596 CVSS 5.3 medium ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the…
- CVE-2026-93595 CVSS 7.1 high ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints…
- CVE-2026-93594 CVSS 7.1 high ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in…
- CVE-2026-93593 CVSS 8.6 high ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions…
- CVE-2026-65831 CVSS 7.7 high ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because…
- CVE-2026-54077 CVSS 7.1 high ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in…
- CVE-2026-54076 CVSS 8.1 high ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to…