SQL Command Access Vulnerability in ArcadeDB by ArcadeData
CVE-2026-54077

7.1HIGH

Key Information:

Vendor

Arcadedata

Vendor
CVE Published:
15 September 2026

What is CVE-2026-54077?

ArcadeDB, a Multi-Model DBMS, has a vulnerability that allows authenticated users to execute SQL commands without proper administrative privileges. This occurs through the IMPORT DATABASE statement, enabling users to initiate server-side requests or access sensitive files on the server. The vulnerability permits exploitation of internal services via HTTP/HTTPS or file:// paths. Additionally, the XML importer supports DTD processing and external entities, which can lead to further security issues. The threat has been addressed in version 26.6.1, implementing stricter permission requirements, restricting local-network imports, and disabling potentially dangerous XML features.

Affected Version(s)

arcadedb < 26.6.1

arcadedb-engine < 26.6.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.