SQL Command Access Vulnerability in ArcadeDB by ArcadeData
CVE-2026-54077
7.1HIGH
What is CVE-2026-54077?
ArcadeDB, a Multi-Model DBMS, has a vulnerability that allows authenticated users to execute SQL commands without proper administrative privileges. This occurs through the IMPORT DATABASE statement, enabling users to initiate server-side requests or access sensitive files on the server. The vulnerability permits exploitation of internal services via HTTP/HTTPS or file:// paths. Additionally, the XML importer supports DTD processing and external entities, which can lead to further security issues. The threat has been addressed in version 26.6.1, implementing stricter permission requirements, restricting local-network imports, and disabling potentially dangerous XML features.
Affected Version(s)
arcadedb < 26.6.1
arcadedb-engine < 26.6.1
