Missing Authentication in ArcadeDB Redis Wire-Protocol Plugin
CVE-2026-75854

9.3CRITICAL

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75854?

The Redis wire-protocol plugin in ArcadeDB prior to version 26.8.1 is susceptible to a missing authentication vulnerability. This flaw enables unauthenticated attackers to gain unauthorized access to the server by connecting to the Redis port. Once connected, attackers can execute arbitrary commands, allowing them to read, write, and even delete sensitive data across any database on the server without needing any credentials, effectively bypassing all existing security measures.

Affected Version(s)

arcadedb 0 < 26.8.1

arcadedb 26.8.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xancyber
manus-use
.