ArcadeDB 是一个多模型数据库管理系统(DBMS)。在 26.6.1 版本之前,针对 CVE-2026-44221 的修复仅在 方法中添加了 权限检查,而位于 和 中的其他公开模式修改(schema mutator)方法仍缺乏相应的权限校验。 因此,任何已认证的标识身份——包括仅有只读 API 令牌但未授予 权限的用户——均可通过数据库的命令/查询 HTTP 端点使用 、 或 等操作,执行以下未授权的模式变更:重命名类型、更改继承关系、修改别名或桶(buckets)、删除属性以及更改属性约束。 虽然此问题不会
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ArcadeData | arcadedb | < 26.6.1 | - |
|
| com.arcadedb | arcadedb-engine | < 26.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65831 | 7.7 HIGH | ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — |
| CVE-2026-54077 | 7.1 HIGH | ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users |
No comments yet