PT-2026-76943 · Arcadedb · Arcadedb

·

CVE-2026-75843

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.8.1
Description An issue exists where the system fails to bind the authenticated principal on the gRPC transaction executor thread within the beginTransaction function. This allows authenticated users with read-only permissions to bypass scripting authorization checks and execute JavaScript commands. By using the executeCommand function with a transaction ID, an attacker can run unrestricted JavaScript to create server-wide administrator accounts.
Recommendations Update ArcadeDB to version 26.8.1 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75843
GHSA-P29F-345W-4QWF

Affected Products

Arcadedb