PT-2026-95376 · Arcadedb · Arcadedb

·

CVE-2026-93597

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.9.1
Description Authenticated attackers can bypass the SSRF guard used by the IMPORT DATABASE and server commands. The system fails to validate IPv6 transition addresses, allowing the use of NAT64, 6to4, or Teredo addresses that embed RFC 1918 or loopback IPv4 payloads. This enables access to internal services and cloud metadata endpoints. SSRF (Server-Side Request Forgery) is a flaw where an attacker forces a server to make requests to an unintended location.
Recommendations Update to version 26.9.1 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93597
GHSA-67M7-7W7G-MPMH

Affected Products

Arcadedb