PT-2026-95377 · Arcadedb · Arcadedb

·

CVE-2026-93598

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.9.1
Description The polyglot script sandbox contains an incomplete deny-list within com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED. While java.util.ResourceBundle is listed, the filter uses exact equality and fails to cover its subclasses, whereas ScriptTriggerExecutor.ALLOWED PACKAGES permits java.util.*. A user with the UPDATE SCHEMA privilege can reference java.util.PropertyResourceBundle or java.util.ListResourceBundle to invoke the static ResourceBundle.getBundle(String) function. This allows the reading of .properties resources from the application classpath, bypassing the sandbox restrictions intended to block access to java.io.**, java.nio.**, and java.net.**. This flaw can lead to the disclosure of sensitive application configurations, including database credentials and API keys, although it does not allow arbitrary host filesystem read or remote code execution.
Recommendations Update to version 26.9.1.

Exploit

Fix

RCE

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93598
GHSA-J57P-QMRH-V7XV

Affected Products

Arcadedb