MAVEN · JULY 2026 · EARLY WARNING

ArcadeDB Privilege Escalation Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-44221CVE-2026-54076CVE-2026-54077GHSA-48QW-824M-86PRSeverity: HIGH

An early warning has been issued regarding a potential privilege escalation vulnerability in ArcadeDB, which could allow a user with read-only privileges to execute arbitrary JVM code and read arbitrary host files.

What happened

Reportedly, a user with read-only privileges on a single database in ArcadeDB could exploit a vulnerability by sending a 'language: js' command to the POST /api/v1/command/{database} HTTP endpoint. This appears to enable the execution of arbitrary JVM code, leading to the potential for arbitrary host file read. The vulnerability is under investigation and affects multiple versions of ArcadeDB, from 21.1.1 to 26.3.2.

To assess your exposure, review the versions of ArcadeDB in use within your organization. The affected versions range from 21.1.1 to 26.3.2, inclusive. It is recommended to consult the primary sources for the most accurate and up-to-date information.

As a precautionary measure, consider upgrading to the latest version of ArcadeDB that includes the fix for the privilege escalation vulnerability. Further details and updates should be obtained from the official ArcadeDB security advisory and GitHub security advisory GHSA-48QW-824M-86PR.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If arcadedb is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats