Insecure Direct Object Reference in ArcadeDB Server from ArcadeData
CVE-2026-75839

5.3MEDIUM

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75839?

Versions of ArcadeDB Server up to 26.7.3 are susceptible to an insecure direct object reference (IDOR) vulnerability. This issue resides within the Raft cluster-info endpoints that authenticate users but fail to authorize access appropriately. As a result, any authenticated user, regardless of their access level, can exploit this flaw when using an ArcadeDB High Availability (HA) cluster configured with the ha-raft module enabled. The vulnerability allows these users to enumerate sensitive details across the entire server database registry, including database names, last transaction IDs, and cluster topology. This can lead to cross-database information disclosure, thereby compromising data privacy. The vulnerability has been addressed in version 26.8.1.

Affected Version(s)

arcadedb 0 < 26.8.1

arcadedb 26.8.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.