PT-2026-76944 · Arcadedb · Arcadedb

·

CVE-2026-75844

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.8.1
Description Authenticated attackers can perform a server-side request forgery (SSRF) via the IMPORT DATABASE command. The issue occurs because the security validator resolves and checks hostnames, but the subsequent connection re-resolves the raw URL and follows redirects. This allows the validator to be bypassed using DNS rebinding or HTTP redirects to access internal services, cloud metadata endpoints, or read arbitrary local files on default installations.
Recommendations Update to version 26.8.1 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75844
GHSA-4W2M-77C8-83MW

Affected Products

Arcadedb