ArcadeDB vulnerabilities
8 CVEs tracked
ArcadeDB appears in supplied reports as a multi-model database with multiple critical vulnerabilities. The primary themes involve sandbox escapes in scripting engines (JavaScript/GraalVM) and pervasive authorization flaws, allowing privileged users to execute unauthorized commands, read arbitrary files, and create user accounts. Additionally, authentication enforcement gaps (SASL, gRPC) enable unauthenticated remote code execution (RCE) and denial of service (DoS) attacks. Defenders should immediately patch to version 26.8.1 or later, scrutinize the MongoDB wire-protocol interface (port 27017), and review permission models.
Azərbaycanca: ArcadeDB, verilən hesabatlarda çoxsaylı kritik boşluqları olan çoxmodelli verilənlər bazası kimi görünür. Əsas mövzu skript mühərriklərində (JavaScript/GraalVM) qum qutusundan çıxma və genişmiqyaslı avtorizasiya yanlışlıqlarıdır ki, bu da imtiyazlı istifadəçilərə icazəsiz əmrlər icra etməyə, faylları oxumağa və istifadəçi yaratmağa imkan verir. Bundan əlavə, autentifikasiya tətbiqindəki (SASL, gRPC) boşluqlar autentifikasiya olunmamış uzaqdan kod icrasına (RCE) və servis inkarı (DoS) hücumlarına şərait yaradır. Müdafiəçilər dərhal 26.8.1 versiyasına və yuxarısına yeniləməli, xüsusilə MongoDB wire-protocol (port 27017) interfeysini nəzarət altına almalı və icazə mexanizmlərini nəzərdən keçirməlidir.
This vendor's CVEs8
This hub is built from skopnix's own reporting on ArcadeDB: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.