Junglewise Threat Intelligence

CVE-2026-18274: Heimdall Data Database Proxy directory traversal RCE in uploadJar

CVE-2026-18274 · Severity: high · CVSS 7.2 · Published 2026-08-20

Executive brief

Heimdall Data Database Proxy is a middleware product used to manage and secure database connections. This vulnerability allows authenticated administrators to upload malicious code via directory traversal, leading to remote code execution with root privileges. An attacker with valid credentials can bypass file upload restrictions and execute arbitrary commands on the database proxy server.

Technical details

The vulnerability exists in the uploadJar method of Heimdall Data Database Proxy, which fails to properly validate user-supplied file paths before using them in file operations. This path traversal flaw allows an authenticated attacker to write files outside the intended upload directory, enabling arbitrary code execution in the context of the root user. The attack vector is network-based and requires valid authentication credentials; no user interaction is necessary once authenticated. An attacker can leverage this to achieve complete system compromise. The vendor released a fix in build 25.03.01.24.

Affected products

  • Heimdall Data Database Proxy prior to 25.03.01.24

Timeline

  • 2026-04-14: disclosed: Vulnerability reported to vendor
  • 2026-07-29: patched: Fixed in release build 25.03.01.24
  • 2026-07-29: advisory: Coordinated public release of advisory ZDI-26-479

References

Related threats