Impact
The vulnerability originates from the IMPORT DATABASE SQL statement, which does not enforce administrative privileges and forwards the supplied source directly to the importer without validation. An authenticated user with SQL command or query API access through /api/v1/command or /api/v1/query can provide HTTP or HTTPS URLs to force internal requests (SSRF) or use file:// paths to read files that the server process can access and incorporate the data as queryable records. The XML importer permits DTD processing and external entities, enabling entity expansion attacks. The root‑only /api/v1/server administration endpoint remains unaffected.
Affected Systems
ArcadeData ArcadeDB and its engine component (com.arcadedb:arcadedb‑engine) are affected. All releases prior to 26.6.1, including 26.5.x and earlier 26.6.0, are vulnerable. Version 26.6.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is below 1%, signifying a very low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalogue. The flaw can be leveraged by any authenticated user with SQL command access; the attack involves submitting a malicious IMPORT DATABASE statement with a crafted URL or file path. The user need not be a database administrator; normal users having command API permissions can trigger SSRF, local file read, or XML external entity attacks. No remote code execution is required, but the information disclosed can be critical for attackers.
OpenCVE Enrichment
Github GHSA