Arbitrary File Read Vulnerability in ArcadeDB by ArcadeData
CVE-2026-75842
8.3HIGH
What is CVE-2026-75842?
ArcadeDB versions prior to 26.8.1 are susceptible to an arbitrary file read vulnerability via the OpenCypher LOAD CSV FROM clause. This flaw enables authenticated users with read query privileges to leverage the file:// protocol within LOAD CSV commands to access and read sensitive local files. Consequently, attackers can exfiltrate critical data directly from server responses, posing significant risks to organizations relying on this database technology.
Affected Version(s)
arcadedb 0 < 26.8.1
arcadedb 26.8.1
