Known Vulnerabilities for Arcadedb by ArcadeData
Listed below are 10 of the newest known vulnerabilities associated with "Arcadedb" by "ArcadeData".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-76225 json | ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fa... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-76224 json | ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin q... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76223 json | ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION... | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-75855 json | ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and dro... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-75854 json | ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows ... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75853 json | ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL P... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75852 json | ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Una... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75851 json | ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal ... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75850 json | ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers.... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-75846 json | ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQ... | Not Provided | 2026-08-18 | 2026-08-18 |