PT-2026-76952 · Arcadedb · Arcadedb
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.8.1
Description
Authenticated root users can perform path traversal—a technique used to access files and directories outside the intended folder—by providing database names containing
../ sequences. This occurs because the software fails to sanitize database names within the create and drop database commands of the 'POST /api/v1/server' endpoint. Consequently, an attacker can create databases at arbitrary filesystem paths or recursively delete directories that the server process has permission to access.Recommendations
Update ArcadeDB to version 26.8.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb