PT-2026-76940 · Arcadedb · Arcadedb

·

CVE-2026-75840

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.8.1
Description An issue exists in the GraalVM JavaScript sandbox allowlist enforcement due to the use of unescaped regular expressions when validating package names. Users with trigger creation privileges can exploit this by using the Java.type() function to access java.util.zip.ZipFile or java.util.jar.JarFile classes, enabling the reading of arbitrary files on the host system with the privileges of the ArcadeDB server process.
Recommendations Update ArcadeDB to version 26.8.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75840
GHSA-WX28-2265-F788

Affected Products

Arcadedb