PT-2026-76944 · Arcadedb · Arcadedb
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.8.1
Description
Authenticated attackers can perform a server-side request forgery (SSRF) via the
IMPORT DATABASE command. The issue occurs because the security validator resolves and checks hostnames, but the subsequent connection re-resolves the raw URL and follows redirects. This allows the validator to be bypassed using DNS rebinding or HTTP redirects to access internal services, cloud metadata endpoints, or read arbitrary local files on default installations.Recommendations
Update to version 26.8.1 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb