Description
ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions do not enforce database-administrator authorization. GraalPolyglotEngine also permits scripts to bypass the allowedPackages whitelist by reflecting from the bound database object through database.getClass().getClassLoader().loadClass to arbitrary host classes. These cooperating defects allow a read-only database user to read arbitrary host files outside the database scope. Process creation is already blocked, so OS command execution is not confirmed. The issue is distinct from CVE-2026-44221, CVE-2026-54076, and CVE-2026-54077. This issue is fixed in version 26.7.1.
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation and arbitrary file read
Action: Immediate patch
AI Analysis

Impact

ArcadeDB, a multi‑model database, allows a user with only a reader role to submit Java Script to the /api/v1/command endpoint because the engine does not enforce database‑administrator authorization on several functions. The scripting engine additionally bypasses package restrictions through class‑loader reflection, giving the user the ability to instantiate any host class. Together these flaws let a read‑only user read files on the host system, outside the database’s file scope, while native process creation remains blocked. The result is a privilege escalation that exposes role, compromising confidentiality and potentially enabling further attacks if additional weaknesses are present.

Affected Systems

Products affected are ArcadeDB and ArcadeDB Server from ArcadeData, with vulnerabilities present in all releases prior to version 26.7.1. The fix is incorporated in 26.7.1 and later releases.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity. EPSS score is <1%, suggesting a very low but non‑zero probability of exploitation, though the vulnerability remains actively exploitable via the web API with a high opportunity for further attack. The issue is not listed in no known large‑scale exploitation at the time of reporting. An attacker controlling a reader‑role account on a vulnerable instance can mount the abuse by sending a JS‑based command request, immediately reading arbitrary host files. No confirmed remote code execution exists, but the read capability may be leveraged in subsequent attacks. The likely attack vector is the Application Layer through the REST API endpoint.

Generated by OpenCVE AI on September 20, 2026 at 16:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the database installation to ArcadeDB 26.7.1 or a later version that applies the security fix
  • If an upgrade is not immediately possible, remove JS users or restrict the /api/v1/command endpoint to administrative accounts
  • Enforce a stricter least‑privilege model by reviewing database user roles and eliminating unnecessary reader permissions on sensitive databases

Generated by OpenCVE AI on September 20, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Arcadedata
Arcadedata arcadedb
Vendors & Products Arcadedata
Arcadedata arcadedb

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions do not enforce database-administrator authorization. GraalPolyglotEngine also permits scripts to bypass the allowedPackages whitelist by reflecting from the bound database object through database.getClass().getClassLoader().loadClass to arbitrary host classes. These cooperating defects allow a read-only database user to read arbitrary host files outside the database scope. Process creation is already blocked, so OS command execution is not confirmed. The issue is distinct from CVE-2026-44221, CVE-2026-54076, and CVE-2026-54077. This issue is fixed in version 26.7.1.
Title ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
Weaknesses CWE-269
CWE-863
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Arcadedata Arcadedb
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T15:41:15.121Z

Reserved: 2026-07-22T23:16:47.752Z

Link: CVE-2026-65831

cve-icon Vulnrichment

Updated: 2026-09-15T15:38:38.716Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:22.387

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-65831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-863

    Incorrect Authorization