


Perceptive Security
SOC/SIEM Consultancy

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.l…
Published:
1 August 2026 at 00:00:00
Alert date:
1 August 2026 at 16:10:41
Source:
nvd.nist.gov
Database & Storage, Web Technologies, Zero-Day Vulnerabilities
ArcadeDB versions before 26.7.2 contain a critical vulnerability in the arcadedb-engine component where the ScriptTriggerExecutor incorrectly adds java.lang.* to the allowed packages for trigger scripts. This allows an authenticated user with UPDATE_SCHEMA permission to create a malicious JavaScript trigger that leverages Java.type to access host classes such as java.lang.Runtime or ProcessBuilder. When the trigger fires, the attacker can execute arbitrary OS commands on the underlying host system. The vulnerability effectively enables remote code execution for any authenticated user with schema update privileges. A patch is available in ArcadeDB version 26.7.2 and later. The issue has been documented in a GitHub security advisory and tracked by VulnCheck.
Technical details
Mitigation steps:
Affected products:
ArcadeDB before 26.7.2
arcadedb-engine
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67340
https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-x9f9-r4m8-9xc2
https://www.vulncheck.com/advisories/arcadedb-before-remote-code-execution-via-trigger-scripts
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
