Description
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java without validation. An authenticated user with SQL command access through /api/v1/command or /api/v1/query can supply HTTP or HTTPS destinations to make server-side requests to internal services, or file:// paths to read files accessible to the server process and ingest the results as queryable records. The XML importer also permits DTD processing and external entities, enabling entity expansion. The root-only /api/v1/server administration endpoint is not affected. The fix requires updateSecurity permission, blocks local-network import destinations by default through arcadedb.server.security.importBlockLocalNetworks, supports the arcadedb.server.security.importAllowedLocalPaths file allow-list, and disables XML DTD processing and external entities. This issue is fixed in version 26.6.1.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑side request forgery and local file read
Action: Immediate Patch
AI Analysis

Impact

The vulnerability originates from the IMPORT DATABASE SQL statement, which does not enforce administrative privileges and forwards the supplied source directly to the importer without validation. An authenticated user with SQL command or query API access through /api/v1/command or /api/v1/query can provide HTTP or HTTPS URLs to force internal requests (SSRF) or use file:// paths to read files that the server process can access and incorporate the data as queryable records. The XML importer permits DTD processing and external entities, enabling entity expansion attacks. The root‑only /api/v1/server administration endpoint remains unaffected.

Affected Systems

ArcadeData ArcadeDB and its engine component (com.arcadedb:arcadedb‑engine) are affected. All releases prior to 26.6.1, including 26.5.x and earlier 26.6.0, are vulnerable. Version 26.6.1 and later contain the fix.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score is below 1%, signifying a very low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalogue. The flaw can be leveraged by any authenticated user with SQL command access; the attack involves submitting a malicious IMPORT DATABASE statement with a crafted URL or file path. The user need not be a database administrator; normal users having command API permissions can trigger SSRF, local file read, or XML external entity attacks. No remote code execution is required, but the information disclosed can be critical for attackers.

Generated by OpenCVE AI on September 20, 2026 at 17:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to ArcadeDB 26.6.1 or later, which implements permission checks, blocks local‑network import destinations by default through arcadedb.server.security.importBlockLocalNetworks, and enforces updateSecurity permission for sensitive operations.
  • Maintain an allow‑list of safe file paths using arcadedb.server.security.importAllowedLocalPaths, and ensure XML external entities and DTD processing remain disabled.
  • Audit SQL command traffic for IMPORT DATABASE statements and monitor logs for attempted SSRF or file read attempts.

Generated by OpenCVE AI on September 20, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8w86-m9h8-hvqg ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Arcadedata
Arcadedata arcadedb
Vendors & Products Arcadedata
Arcadedata arcadedb

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java without validation. An authenticated user with SQL command access through /api/v1/command or /api/v1/query can supply HTTP or HTTPS destinations to make server-side requests to internal services, or file:// paths to read files accessible to the server process and ingest the results as queryable records. The XML importer also permits DTD processing and external entities, enabling entity expansion. The root-only /api/v1/server administration endpoint is not affected. The fix requires updateSecurity permission, blocks local-network import destinations by default through arcadedb.server.security.importBlockLocalNetworks, supports the arcadedb.server.security.importAllowedLocalPaths file allow-list, and disables XML DTD processing and external entities. This issue is fixed in version 26.6.1.
Title ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
Weaknesses CWE-22
CWE-776
CWE-918
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Arcadedata Arcadedb
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T15:44:11.572Z

Reserved: 2026-06-11T18:44:47.760Z

Link: CVE-2026-54077

cve-icon Vulnrichment

Updated: 2026-09-15T15:44:06.616Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:13.710

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:30:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-776

    Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

  • CWE-918

    Server-Side Request Forgery (SSRF)