Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75844— ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass

CVSS 7.1 · High EPSS 0.23% · P14

Affected Version Matrix 2

VendorProductVersion RangeStatus
ArcadeDataarcadedb< 26.8.1affected
26.8.1unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-75844

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass
Source: CVE Program / CVE List V5
Vulnerability Description
ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the subsequent connection re-resolves the raw URL and follows redirects. Authenticated attackers can bypass the validator using DNS rebinding or HTTP redirects to access cloud metadata endpoints, internal services, or read arbitrary local files on default installations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5
Vulnerability Title
Arcade Data ArcadeDB 服务端请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Arcade Data ArcadeDB是Arcade Data组织的一款高性能原生多模型数据库。 Arcade Data ArcadeDB 26.8.1之前版本存在服务端请求伪造漏洞,该漏洞源于IMPORT DATABASE命令中安全验证器解析并检查主机名后,后续连接重新解析原始URL并跟随重定向,可能导致经过身份验证的攻击者利用DNS重绑定或HTTP重定向绕过验证器,访问云元数据端点、内部服务或读取任意本地文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
ArcadeDataarcadedb 0 ~ 26.8.1 -

II. Public POCs for CVE-2026-75844

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 8029 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-75844

登录查看更多情报信息。

Vendor Advisories for CVE-2026-75844 (2)

Same Patch Batch · ArcadeData · 2026-08-18 · 14 CVEs total

CVE-2026-758439.9 CRITICALArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction
CVE-2026-758519.9 CRITICALArcadeDB before 26.8.1 Authentication Bypass via Async Command
CVE-2026-758549.8 CRITICALArcadeDB Redis Wire-Protocol Plugin Missing Authentication
CVE-2026-758529.8 CRITICALArcadeDB MongoDB wire protocol authentication bypass cross-database
CVE-2026-758538.8 HIGHArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database
CVE-2026-758558.7 HIGHArcadeDB before 26.8.1 Path Traversal via create/drop database
CVE-2026-758427.7 HIGHArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV
CVE-2026-758407.5 HIGHArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex
CVE-2026-758467.1 HIGHArcadeDB before 26.8.1 Unauthorized Function Deletion via DELETE FUNCTION
CVE-2026-758456.3 MEDIUMArcadeDB 26.4.2 before 26.8.1 Authorization Bypass via set_server_setting
CVE-2026-758414.3 MEDIUMArcadeDB before 26.8.1 Denial of Service via range()
CVE-2026-758394.3 MEDIUMArcadeDB before 26.8.1 Information Disclosure via Cluster Endpoints
CVE-2026-758504.2 MEDIUMArcadeDB before 26.8.1 Per-Type ACL Bypass via Batch Handlers

IV. Related Vulnerabilities

V. Comments for CVE-2026-75844

No comments yet


Leave a comment