ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the subsequent connection re-resolves the raw URL and follows redirects. Authenticated attackers can bypass the validator using DNS rebinding or HTTP redirects to access cloud metadata endpoints, internal services, or read arbitrary local files on default installations.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arcadedata
Arcadedata arcadedb |
|
| Vendors & Products |
Arcadedata
Arcadedata arcadedb |
Tue, 18 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the subsequent connection re-resolves the raw URL and follows redirects. Authenticated attackers can bypass the validator using DNS rebinding or HTTP redirects to access cloud metadata endpoints, internal services, or read arbitrary local files on default installations. | |
| Title | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T13:35:55.096Z
Reserved: 2026-08-18T10:59:33.701Z
Link: CVE-2026-75844
No data.
Status : Received
Published: 2026-08-18T12:19:34.890
Modified: 2026-08-18T14:18:11.957
Link: CVE-2026-75844
No data.
OpenCVE Enrichment
Updated: 2026-08-18T12:45:06Z