Known Vulnerabilities for Arcadedb by ArcadeData
Listed below are 9 of the newest known vulnerabilities associated with "Arcadedb" by "ArcadeData".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68578 json | ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permis... | Not Provided | 2026-08-02 | 2026-08-03 |
| CVE-2026-67357 json | ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leak... | Not Provided | 2026-08-02 | 2026-08-03 |
| CVE-2026-67356 json | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing sch... | Not Provided | 2026-08-02 | 2026-08-03 |
| CVE-2026-67344 json | ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ...... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67343 json | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authen... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67342 json | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Promet... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67341 json | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANG... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67340 json | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) becaus... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-44221 json | ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens s... | Not Provided | 2026-05-12 | 2026-08-03 |