NPM · AUGUST 2026 · CONFIRMED

ArcadeDB < 26.7.2: Critical Vulnerabilities Allow OS Command Execution

CVE-2026-67340Severity: CRITICAL

ArcadeDB versions before 26.7.2 contain critical vulnerabilities that allow authenticated users to execute arbitrary OS commands, impacting systems using affected versions.

What happened

ArcadeDB versions prior to 26.7.2 are affected by multiple critical vulnerabilities (CVE-2026-67340, CVE-2026-67341, CVE-2026-67342) that enable authenticated users to execute arbitrary operating system commands. These vulnerabilities stem from improper authorization checks and script execution controls. Specifically, trigger scripts can access java.lang.* classes, SQL DEFINE FUNCTION statements lack scripting authorization checks, and HTTP handlers for various endpoints fail to validate database access permissions. To assess exposure, check if your system uses ArcadeDB versions before 26.7.2. Upgrade to version 26.7.2 or later to mitigate these risks.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If arcadedb is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats