Description
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare class name, which is matched by exact equality and therefore does not cover its subclasses, while ScriptTriggerExecutor.ALLOWED_PACKAGES permits java.util.*. A user with the UPDATE_SCHEMA privilege (sufficient to create or alter a JavaScript trigger; no server-admin rights required) can reference java.util.PropertyResourceBundle or java.util.ListResourceBundle and invoke the inherited static ResourceBundle.getBundle(String) to read .properties resources from the application classpath, which the sandbox (IOAccess.NONE, with java.io.**, java.nio.** and java.net.** denied) is intended to make unreachable. This can disclose packaged application configuration such as database credentials and API keys; the advisory states the issue does not provide arbitrary host filesystem read or remote code execution. Fixed in 26.9.1.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Disclosure
Action: Immediate Patch
AI Analysis

Impact

An incomplete deny‑list in ArcadeDB’s polyglot script sandbox permits scripts with UPDATE_SCHEMA privilege to reference subclasses of java.util.ResourceBundle and invoke ResourceBundle.getBundle(String). This grants the ability to read .properties files on the application classpath, exposing configuration such as database credentials and API keys. The flaw does not allow arbitrary filesystem access or remote code execution. CWE-184 applies.

Affected Systems

ArcadeData ArcadeDB versions prior to 26.9.1, specifically 26.8.1 and earlier, are affected. The vulnerability resides in the com.arcadedb:arcadedb-engine artifact, and the fix is released in 26.9.1. Users running earlier releases should be aware that any application classpath containing sensitive .properties files is at risk.

Risk and Exploitability

With a CVSS score of 7.1, the vulnerability presents a medium‑to‑high risk. The EPSS score is less than 1%, indicating a very low likelihood of exploitation. The issue is not listed in CISA’s KEV catalog. Exploitation requires a user with UPDATE_SCHEMA privilege, which is sufficient to create or modify JavaScript triggers. Attackers would need to craft a trigger that references java.util.PropertyResourceBundle or java.util.ListResourceBundle to call getBundle and read the desired properties file. The sandbox’s IO restrictions are ineffective for this subclass scenario, but the flaw does not provide broader file system reading or code execution capabilities.

Generated by OpenCVE AI on September 19, 2026 at 18:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ArcadeDB to version 26.9.1 or later to apply the vendor patch.
  • If an upgrade is not immediately possible, revoke or restrict UPDATE_SCHEMA privileges for users that do not require schema modification, preventing the creation of malicious JavaScript triggers.
  • Remove or obfuscate sensitive configuration files from the application classpath, or place them in a location inaccessible to the JavaScript sandbox environment.
  • Configure the polyglot sandbox to deny access to java.util.ResourceBundle and its subclasses explicitly by adding fully qualified names to the deny list.

Generated by OpenCVE AI on September 19, 2026 at 18:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Arcadedata
Arcadedata arcadedb
Vendors & Products Arcadedata
Arcadedata arcadedb

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare class name, which is matched by exact equality and therefore does not cover its subclasses, while ScriptTriggerExecutor.ALLOWED_PACKAGES permits java.util.*. A user with the UPDATE_SCHEMA privilege (sufficient to create or alter a JavaScript trigger; no server-admin rights required) can reference java.util.PropertyResourceBundle or java.util.ListResourceBundle and invoke the inherited static ResourceBundle.getBundle(String) to read .properties resources from the application classpath, which the sandbox (IOAccess.NONE, with java.io.**, java.nio.** and java.net.** denied) is intended to make unreachable. This can disclose packaged application configuration such as database credentials and API keys; the advisory states the issue does not provide arbitrary host filesystem read or remote code execution. Fixed in 26.9.1.
Title ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle
Weaknesses CWE-184
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Arcadedata Arcadedb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T14:24:25.221Z

Reserved: 2026-09-18T11:00:32.755Z

Link: CVE-2026-93598

cve-icon Vulnrichment

Updated: 2026-09-22T14:23:43.924Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:11.247

Modified: 2026-09-22T15:17:23.913

Link: CVE-2026-93598

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:15Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs