Impact
An incomplete deny‑list in ArcadeDB’s polyglot script sandbox permits scripts with UPDATE_SCHEMA privilege to reference subclasses of java.util.ResourceBundle and invoke ResourceBundle.getBundle(String). This grants the ability to read .properties files on the application classpath, exposing configuration such as database credentials and API keys. The flaw does not allow arbitrary filesystem access or remote code execution. CWE-184 applies.
Affected Systems
ArcadeData ArcadeDB versions prior to 26.9.1, specifically 26.8.1 and earlier, are affected. The vulnerability resides in the com.arcadedb:arcadedb-engine artifact, and the fix is released in 26.9.1. Users running earlier releases should be aware that any application classpath containing sensitive .properties files is at risk.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability presents a medium‑to‑high risk. The EPSS score is less than 1%, indicating a very low likelihood of exploitation. The issue is not listed in CISA’s KEV catalog. Exploitation requires a user with UPDATE_SCHEMA privilege, which is sufficient to create or modify JavaScript triggers. Attackers would need to craft a trigger that references java.util.PropertyResourceBundle or java.util.ListResourceBundle to call getBundle and read the desired properties file. The sandbox’s IO restrictions are ineffective for this subclass scenario, but the flaw does not provide broader file system reading or code execution capabilities.
OpenCVE Enrichment