Arcade Data ArcadeDB是Arcade Data组织的一款高性能原生多模型数据库。 Arcade Data ArcadeDB 26.8.1之前版本存在资源管理错误漏洞,该漏洞源于Cypher range()函数处理不当,可能导致认证用户提交超大的range()表达式,耗尽服务器堆内存,触发OutOfMemoryError,导致服务暂时降级或不可用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ArcadeData | arcadedb | < 26.8.1 |
affected |
26.8.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ArcadeData | arcadedb | 0 ~ 26.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75843 | 9.9 CRITICAL | ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction |
| CVE-2026-75851 | 9.9 CRITICAL | ArcadeDB before 26.8.1 Authentication Bypass via Async Command |
| CVE-2026-75854 | 9.8 CRITICAL | ArcadeDB Redis Wire-Protocol Plugin Missing Authentication |
| CVE-2026-75852 | 9.8 CRITICAL | ArcadeDB MongoDB wire protocol authentication bypass cross-database |
| CVE-2026-75853 | 8.8 HIGH | ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database |
| CVE-2026-75855 | 8.7 HIGH | ArcadeDB before 26.8.1 Path Traversal via create/drop database |
| CVE-2026-75842 | 7.7 HIGH | ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV |
| CVE-2026-75840 | 7.5 HIGH | ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex |
| CVE-2026-75846 | 7.1 HIGH | ArcadeDB before 26.8.1 Unauthorized Function Deletion via DELETE FUNCTION |
| CVE-2026-75844 | 7.1 HIGH | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass |
| CVE-2026-75845 | 6.3 MEDIUM | ArcadeDB 26.4.2 before 26.8.1 Authorization Bypass via set_server_setting |
| CVE-2026-75839 | 4.3 MEDIUM | ArcadeDB before 26.8.1 Information Disclosure via Cluster Endpoints |
| CVE-2026-75850 | 4.2 MEDIUM | ArcadeDB before 26.8.1 Per-Type ACL Bypass via Batch Handlers |
No comments yet