com.arcadedb:arcadedb-engine
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.arcadedb:arcadedb-enginepage 1 of 1
- CVE-2026-54076HIGHCVSS 8.1EG 8.1✓ Fixed in 26.6.12026-07-16
vulnerable: 21.10.1 ... 26.5.1 (56 versions)
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcaded…
- CVE-2026-54077HIGHCVSS 7.1EG 7.1✓ Fixed in 26.6.12026-07-16
vulnerable: 21.10.1 ... 26.5.1 (56 versions)
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integratio…
- CVE-2026-67340CRITICALCVSS 7.2EG 9.8✓ Fixed in 26.7.22026-08-01
vulnerable: 21.10.1 ... 26.7.1 (58 versions)
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permiss…
- CVE-2026-67341CRITICALCVSS 9.8EG 9.8✓ Fixed in 26.7.22026-08-01
vulnerable: 21.10.1 ... 26.7.1 (58 versions)
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statem…
Check whether com.arcadedb:arcadedb-engine is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.arcadedb:arcadedb-engine CVEs against the assets you own.
Start Free Scan →