Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Chow8386

#15562of 56,335
18.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-78406
8.8
2026-08-19
Arcadedb · Arcadedb · CVE-2026-76224
**Name of the Vulnerable Software and Affected Versions** ArcadeDB versions prior to 26.8.1 **Description** The Gremlin query engine contains a flaw where the `ArcadeGremlin.executeStatement()` function silently reverts to an insecure Groovy engine if a request includes any query parameter and the query fails to parse as gremlin-lang, despite the default being the secure java engine. An authenticated user with any database role, including read-only access, can exploit this by submitting a parameterized Gremlin query to execute arbitrary operating system commands with the privileges of the ArcadeDB server process user. **Recommendations** Update ArcadeDB to version 26.8.1 or later.
PT-2026-76949
9.8
2026-08-18
Arcadedb · Arcadedb · CVE-2026-75852
**Name of the Vulnerable Software and Affected Versions** ArcadeDB versions prior to 26.8.1 **Description** The MongoDB wire-protocol plugin fails to enforce SASL (Simple Authentication and Security Layer) authentication on data commands. This allows unauthenticated attackers to connect to port 27017 without credentials and execute commands such as insert, find, update, delete, and create against any database. **Recommendations** Update to version 26.8.1 or later.