Impact
The vulnerability arises from a missing authentication check in the Redis wire-protocol plugin of ArcadeDB. Because the plugin accepts connections on the standard Redis port without verifying credentials, an external attacker can read, modify, or delete any database instance present on the server. This exposes the database to unauthorized disclosure of sensitive data, loss of integrity, and potential service degradation. The vulnerability is identified as CWE-306.
Affected Systems
Vulnerable installations are ArcadeData ArcadeDB versions earlier than 26.8.1. Any deployment that has the Redis wire-protocol plugin enabled during this timeframe is susceptible. The affected product is the ArcadeData ArcadeDB database platform.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score of 1% indicates a very low but non‑zero probability of exploitation; nevertheless, the lack of authentication allows an attacker to simply connect to the Redis port if it is exposed. The attack surface is therefore broad, and a remote attacker can perform arbitrary commands against all databases on the host. Since the vulnerability is not listed in the CISA KEV catalog, there is no known public exploit; however, the weakness in authentication makes it highly attractive for attackers targeting exploitable services.
OpenCVE Enrichment