PT-2026-95376 · Arcadedb · Arcadedb
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.9.1
Description
Authenticated attackers can bypass the SSRF guard used by the
IMPORT DATABASE and server commands. The system fails to validate IPv6 transition addresses, allowing the use of NAT64, 6to4, or Teredo addresses that embed RFC 1918 or loopback IPv4 payloads. This enables access to internal services and cloud metadata endpoints. SSRF (Server-Side Request Forgery) is a flaw where an attacker forces a server to make requests to an unintended location.Recommendations
Update to version 26.9.1 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb