ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}. Because those workers hav
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ArcadeData | arcadedb | 0 ~ 26.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93594 | 8.1 HIGH | ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries |
| CVE-2026-93593 | 8.1 HIGH | ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission |
| CVE-2026-93597 | 7.7 HIGH | ArcadeDB before 26.9.1 SSRF via IPv6 transition addresses |
| CVE-2026-93598 | 7.1 HIGH | ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle |
| CVE-2026-93595 | 6.5 MEDIUM | ArcadeDB before 26.9.1 ACL Bypass via query_database Tool |
No comments yet