com.arcadedb:arcadedb-engine
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.arcadedb:arcadedb-enginepage 1 of 1
- CVE-2026-54076HIGHCVSS 8.1EG 8.1✓ Fixed in 26.6.12026-07-16
vulnerable: 21.10.1 ... 26.5.1 (56 versions)
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221) ### Impact The fix for CVE-2026-44221 (GHSA-fxc7-fm93-6q77) added an `UPDATE_SCHEMA` authorization check to a single schema-mutating method (`LocalDo…
- CVE-2026-54077HIGHCVSS 7.1EG 7.1✓ Fixed in 26.6.12026-07-16
vulnerable: 21.10.1 ... 26.5.1 (56 versions)
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users ### Impact The SQL `IMPORT DATABASE` statement did not require administrative privileges and passed its source URL to the importer without validat…
- CVE-2026-67340CRITICALCVSS 7.2EG 9.8✓ Fixed in 26.7.22026-08-01
vulnerable: 21.10.1 ... 26.7.1 (58 versions)
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permiss…
- CVE-2026-67341CRITICALCVSS 9.8EG 9.8✓ Fixed in 26.7.22026-08-01
vulnerable: 21.10.1 ... 26.7.1 (58 versions)
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statem…
Check whether com.arcadedb:arcadedb-engine is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.arcadedb:arcadedb-engine CVEs against the assets you own.
Start Free Scan →