Arcade Data ArcadeDB是Arcade Data组织的一款高性能原生多模型数据库。 ArcadeData arcadedb 26.4.2至26.7.3版本存在权限许可和访问控制问题漏洞,该漏洞源于set_server_setting MCP服务器级工具的SetServerSettingTool.execute()方法仅检查全局allowAdmin标志而未检查调用者角色,可能导致经过身份验证的只读用户调用set_server_setting修改服务器GlobalConfiguration,从
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ArcadeData | arcadedb | 26.4.2< 26.8.1 |
affected |
26.8.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ArcadeData | arcadedb | 26.4.2 ~ 26.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75843 | 9.9 CRITICAL | ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction |
| CVE-2026-75851 | 9.9 CRITICAL | ArcadeDB before 26.8.1 Authentication Bypass via Async Command |
| CVE-2026-75854 | 9.8 CRITICAL | ArcadeDB Redis Wire-Protocol Plugin Missing Authentication |
| CVE-2026-75852 | 9.8 CRITICAL | ArcadeDB MongoDB wire protocol authentication bypass cross-database |
| CVE-2026-75853 | 8.8 HIGH | ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database |
| CVE-2026-75855 | 8.7 HIGH | ArcadeDB before 26.8.1 Path Traversal via create/drop database |
| CVE-2026-75842 | 7.7 HIGH | ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV |
| CVE-2026-75840 | 7.5 HIGH | ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex |
| CVE-2026-75846 | 7.1 HIGH | ArcadeDB before 26.8.1 Unauthorized Function Deletion via DELETE FUNCTION |
| CVE-2026-75844 | 7.1 HIGH | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass |
| CVE-2026-75841 | 4.3 MEDIUM | ArcadeDB before 26.8.1 Denial of Service via range() |
| CVE-2026-75839 | 4.3 MEDIUM | ArcadeDB before 26.8.1 Information Disclosure via Cluster Endpoints |
| CVE-2026-75850 | 4.2 MEDIUM | ArcadeDB before 26.8.1 Per-Type ACL Bypass via Batch Handlers |
No comments yet