Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ganiganesh25

#32048of 56,330
8.7Total CVSS
Vulnerabilities · 1
PT-2026-76940
8.7
2026-08-18
Arcadedb · Arcadedb · CVE-2026-75840
**Name of the Vulnerable Software and Affected Versions** ArcadeDB versions prior to 26.8.1 **Description** An issue exists in the GraalVM JavaScript sandbox allowlist enforcement due to the use of unescaped regular expressions when validating package names. Users with trigger creation privileges can exploit this by using the `Java.type()` function to access `java.util.zip.ZipFile` or `java.util.jar.JarFile` classes, enabling the reading of arbitrary files on the host system with the privileges of the ArcadeDB server process. **Recommendations** Update ArcadeDB to version 26.8.1 or later.