Known Vulnerabilities for Arcadedb by ArcadeData
Listed below are 10 of the newest known vulnerabilities associated with "Arcadedb" by "ArcadeData".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-93598 json | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-93597 json | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and serv... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-93596 json | ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAs... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-93595 json | ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-93594 json | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules o... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-93593 json | ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-76225 json | ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fa... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-76224 json | ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin q... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76223 json | ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION... | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-75855 json | ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and dro... | Not Provided | 2026-08-18 | 2026-08-19 |