ArcadeDB 是一个多模型数据库管理系统(Multi-Model DBMS)。在 26.7.1 版本之前,具有“读取”(reader)权限的用户可以通过向 发送带有 的 POST 请求来执行操作。这是因为 、 和 均未强制要求数据库管理员权限进行授权检查。此外, 还允许脚本通过 从绑定的数据库对象进行反射,从而绕过 白名单,加载任意的宿主类。 这些相互关联的缺陷使得仅具有只读权限的数据库用户能够读取数据库范围之外的任意宿主文件。虽然进程创建功能已被阻止,但尚未确认是否可以进行操作系统命令执行。该问题与 CVE-
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ArcadeData | arcadedb | < 26.7.1 | - |
|
| com.arcadedb | arcadedb-server | < 26.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54076 | 8.1 HIGH | ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221) |
| CVE-2026-54077 | 7.1 HIGH | ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users |
No comments yet