PT-2026-78406 · Arcadedb · Arcadedb

·

CVE-2026-76224

·

Published

2026-08-19

·

Updated

2026-08-20

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.8.1
Description The Gremlin query engine contains a flaw where the ArcadeGremlin.executeStatement() function silently reverts to an insecure Groovy engine if a request includes any query parameter and the query fails to parse as gremlin-lang, despite the default being the secure java engine. An authenticated user with any database role, including read-only access, can exploit this by submitting a parameterized Gremlin query to execute arbitrary operating system commands with the privileges of the ArcadeDB server process user.
Recommendations Update ArcadeDB to version 26.8.1 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76224
GHSA-WCM5-4WJM-9WJ3

Affected Products

Arcadedb