Impact
ArcadeDB, a multi‑model database, allows a user with only a reader role to submit Java Script to the /api/v1/command endpoint because the engine does not enforce database‑administrator authorization on several functions. The scripting engine additionally bypasses package restrictions through class‑loader reflection, giving the user the ability to instantiate any host class. Together these flaws let a read‑only user read files on the host system, outside the database’s file scope, while native process creation remains blocked. The result is a privilege escalation that exposes role, compromising confidentiality and potentially enabling further attacks if additional weaknesses are present.
Affected Systems
Products affected are ArcadeDB and ArcadeDB Server from ArcadeData, with vulnerabilities present in all releases prior to version 26.7.1. The fix is incorporated in 26.7.1 and later releases.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. EPSS score is <1%, suggesting a very low but non‑zero probability of exploitation, though the vulnerability remains actively exploitable via the web API with a high opportunity for further attack. The issue is not listed in no known large‑scale exploitation at the time of reporting. An attacker controlling a reader‑role account on a vulnerable instance can mount the abuse by sending a JS‑based command request, immediately reading arbitrary host files. No confirmed remote code execution exists, but the read capability may be leveraged in subsequent attacks. The likely attack vector is the Application Layer through the REST API endpoint.
OpenCVE Enrichment