PT-2026-76952 · Arcadedb · Arcadedb

·

CVE-2026-75855

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.8.1
Description Authenticated root users can perform path traversal—a technique used to access files and directories outside the intended folder—by providing database names containing ../ sequences. This occurs because the software fails to sanitize database names within the create and drop database commands of the 'POST /api/v1/server' endpoint. Consequently, an attacker can create databases at arbitrary filesystem paths or recursively delete directories that the server process has permission to access.
Recommendations Update ArcadeDB to version 26.8.1 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75855
GHSA-QWGR-2C45-63XX

Affected Products

Arcadedb