Path Traversal Vulnerability in ArcadeDB by ArcadeData
CVE-2026-75855
8.4HIGH
What is CVE-2026-75855?
ArcadeDB versions prior to 26.8.1 are vulnerable to a path traversal issue within the POST /api/v1/server endpoint, specifically in the create database and drop database commands. This vulnerability allows authenticated root users to manipulate database names by including ../ sequences, enabling them to create databases at arbitrary file system locations or to delete directories that the server process has access to. This poses a significant risk as it can lead to unauthorized file writes or deletions beyond the expected database directory.
Affected Version(s)
arcadedb 0 < 26.8.1
arcadedb 26.8.1
