Path Traversal Vulnerability in ArcadeDB by ArcadeData
CVE-2026-75855

8.4HIGH

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75855?

ArcadeDB versions prior to 26.8.1 are vulnerable to a path traversal issue within the POST /api/v1/server endpoint, specifically in the create database and drop database commands. This vulnerability allows authenticated root users to manipulate database names by including ../ sequences, enabling them to create databases at arbitrary file system locations or to delete directories that the server process has access to. This poses a significant risk as it can lead to unauthorized file writes or deletions beyond the expected database directory.

Affected Version(s)

arcadedb 0 < 26.8.1

arcadedb 26.8.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pervinzahidli
.