Arbitrary File Read Vulnerability in ArcadeDB by ArcadeData
CVE-2026-75840
8.7HIGH
What is CVE-2026-75840?
ArcadeDB prior to version 26.8.1 is susceptible to an arbitrary file read vulnerability due to improper enforcement of allowlisting within the GraalVM JavaScript sandbox. The flaw stems from the use of unescaped regular expressions for package name validation, allowing attackers with trigger creation rights to exploit Java.type() to access java.util.zip.ZipFile or java.util.jar.JarFile classes. As a result, unauthorized users can potentially read arbitrary files on the host system where the ArcadeDB server operates.
Affected Version(s)
arcadedb 0 < 26.8.1
arcadedb 26.8.1
