Insecure Direct Object Reference in ArcadeDB Server from ArcadeData
CVE-2026-75839
What is CVE-2026-75839?
Versions of ArcadeDB Server up to 26.7.3 are susceptible to an insecure direct object reference (IDOR) vulnerability. This issue resides within the Raft cluster-info endpoints that authenticate users but fail to authorize access appropriately. As a result, any authenticated user, regardless of their access level, can exploit this flaw when using an ArcadeDB High Availability (HA) cluster configured with the ha-raft module enabled. The vulnerability allows these users to enumerate sensitive details across the entire server database registry, including database names, last transaction IDs, and cluster topology. This can lead to cross-database information disclosure, thereby compromising data privacy. The vulnerability has been addressed in version 26.8.1.
Affected Version(s)
arcadedb 0 < 26.8.1
arcadedb 26.8.1
