What is CVE-2026-75844?
ArcadeDB versions prior to 26.8.1 contain a server-side request forgery (SSRF) vulnerability in the IMPORT DATABASE command. The security validator resolves hostnames but the subsequent connection re-resolves the raw URL and follows redirects, allowing authenticated attackers to bypass validation and send unauthorized requests to internal systems. Immediate upgrade to version 26.8.1 or later is recommended to mitigate this issue.
Azərbaycanca: ArcadeDB-nin 26.8.1-dən əvvəlki versiyalarında IMPORT DATABASE əmrində server-side request forgery (SSRF) zəifliyi aşkar edilib. Təsdiqlənmiş istifadəçilər təhlükəsizlik validasiyasını keçərək daxili sistemlərə icazəsiz sorğular göndərə bilər. Bu problemi aradan qaldırmaq üçün dərhal 26.8.1 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of ArcadeDB are affected by CVE-2026-75844?
CVE-2026-75844 affects ArcadeDB versions prior to 26.8.1.
Does exploiting this SSRF vulnerability require authentication?
Yes, exploiting CVE-2026-75844 requires the attacker to be an authenticated user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.