← Retour à la recherche de CVE

CVE-2026-76224

ArcadeDB

Description

ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure java (gremlin-lang) engine, ArcadeGremlin.executeStatement() silently falls back to the insecure Groovy engine whenever a request carries any query parameter and the query does not parse as gremlin-lang. An authenticated user with any database role, including a read-only reader, can submit a parameterized Gremlin query to trigger the Groovy fallback and execute arbitrary operating system commands as the ArcadeDB server process user.

CVSS 8.8EPSS 0.583%Risque 0.93
Voir la source
Publication
2026-08-19 14:17:48
Versions concernées
<26.8.1
Type
Bibliothèque
Dernière modification
2026-08-20 16:18:09
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H