What is CVE-2026-75851?
CVE-2026-75851 is a vulnerability in ArcadeDB server versions 26.7.3 and earlier, where the authenticated principal is not propagated to asynchronous command worker threads. When commands are issued with `awaitResponse:false`, the async workers execute without a bound user context, potentially allowing unauthorized operations. Affected systems should be upgraded to the latest patched version immediately.
Azərbaycanca: CVE-2026-75851, ArcadeDB server-in 26.7.3 və daha əvvəlki versiyalarında aşkarlanan boşluqdur. Bu zəiflik `awaitResponse:false` ilə HTTP sorğuları göndərildikdə asinxron əmrlərin autentifikasiya olunmuş istifadəçi konteksti olmadan işləməsinə səbəb olur, bu da icazəsiz əməliyyatlara yol aça bilər. Bu versiyaları istifadə edən sistemlər dərhal ən son təhlükəsizlik yeniləməsinə qədər yüksəldilməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of ArcadeDB are affected by CVE-2026-75851?
ArcadeDB server versions 26.7.3 and earlier are affected by this vulnerability.
How can CVE-2026-75851 be exploited?
When HTTP requests are sent with `awaitResponse:false`, the asynchronous commands execute without a bound user context, potentially allowing unauthorized operations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.