top of page
perceptive_background_267k.jpg

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.l…

Published:

31 July 2026 at 22:00:00

Alert date:

1 August 2026 at 14:10:41

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Web Technologies, Zero-Day Vulnerabilities

ArcadeDB versions before 26.7.2 contain a critical vulnerability in the arcadedb-engine component where the ScriptTriggerExecutor incorrectly adds java.lang.* to the allowed packages for trigger scripts. This allows an authenticated user with UPDATE_SCHEMA permission to create a malicious JavaScript trigger that leverages Java.type to access host classes such as java.lang.Runtime or ProcessBuilder. When the trigger fires, the attacker can execute arbitrary OS commands on the underlying host system. The vulnerability effectively enables remote code execution for any authenticated user with schema update privileges. A patch is available in ArcadeDB version 26.7.2 and later. The issue has been documented in a GitHub security advisory and tracked by VulnCheck.

Technical details

Mitigation steps:

Affected products:

ArcadeDB before 26.7.2
arcadedb-engine

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page