PT-2026-95377 · Arcadedb · Arcadedb
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.9.1
Description
The polyglot script sandbox contains an incomplete deny-list within
com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED. While java.util.ResourceBundle is listed, the filter uses exact equality and fails to cover its subclasses, whereas ScriptTriggerExecutor.ALLOWED PACKAGES permits java.util.*. A user with the UPDATE SCHEMA privilege can reference java.util.PropertyResourceBundle or java.util.ListResourceBundle to invoke the static ResourceBundle.getBundle(String) function. This allows the reading of .properties resources from the application classpath, bypassing the sandbox restrictions intended to block access to java.io.**, java.nio.**, and java.net.**. This flaw can lead to the disclosure of sensitive application configurations, including database credentials and API keys, although it does not allow arbitrary host filesystem read or remote code execution.Recommendations
Update to version 26.9.1.
Exploit
Fix
RCE
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb