ArcadeDB 是一个多模型数据库管理系统(Multi-Model DBMS)。在 26.6.1 版本之前,位于 中的 语句未要求管理权限,并且将其源参数未经验证地传递给了 。 拥有通过 或 执行 SQL 命令权限的已认证用户,可以指定 HTTP 或 HTTPS 目标地址,从而诱导服务器向内部服务发起请求(服务端请求伪造,SSRF),或者使用 协议路径读取服务器进程可访问的文件,并将读取结果作为可查询的记录导入。此外,XML 导入器允许处理 DTD 和外部实体,可能导致实体扩展攻击(XXE)。 仅管理员可用的 管
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ArcadeData | arcadedb | < 26.6.1 | - |
|
| com.arcadedb | arcadedb-engine | < 26.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54076 | 8.1 HIGH | ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221) |
| CVE-2026-65831 | 7.7 HIGH | ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — |
No comments yet