What is CVE-2026-75843?
ArcadeDB versions before 26.8.1 fail to bind the authenticated principal on the gRPC transaction executor thread, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Users should immediately upgrade to ArcadeDB version 26.8.1 or later.
Azərbaycanca: ArcadeDB 26.8.1-dən əvvəlki versiyalarda gRPC tranzaksiya icraçı ipində authenticated principal-in bağlanmaması boşluğu aşkarlanıb. Bu, authenticated reader-lərə skript avtorizasiya yoxlamaları olmadan JavaScript əmrləri icra etməyə imkan verir. İstifadəçilər dərhal ArcadeDB-ni 26.8.1 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: ArcadeDB
FAQ2
Which versions of ArcadeDB are affected by CVE-2026-75843?
This vulnerability affects ArcadeDB versions before 26.8.1.
What operation can an authenticated reader perform by exploiting CVE-2026-75843?
An authenticated reader can execute JavaScript commands without scripting authorization checks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.