Junglewise Threat Intelligence

CVE-2026-75839: ArcadeDB insecure direct object reference in Raft cluster endpoints

CVE-2026-75839 · Severity: medium · CVSS 4.3 · Published 2026-08-18

Technologies: ArcadeData ArcadeDB. Vendors: ArcadeData.

Executive brief

ArcadeDB is a distributed database server that supports high-availability clustering. An insecure authorization flaw in its Raft cluster-info endpoints allows any authenticated user—even those with no database access—to discover all databases on the server and retrieve sensitive metadata including database names, transaction IDs, and cluster topology information. This enables an attacker to perform reconnaissance on other tenants' databases without authorization.

Technical details

The vulnerability is an insecure direct object reference (IDOR) combined with missing authorization checks in GetClusterHandler and PostBootstrapStateHandler. Both endpoints perform authentication but omit authorization logic (canAccessToDatabase, getAuthorizedDatabases, or checkRootUser calls) present in similar Raft mutation endpoints. The handlers iterate over the full server database registry via getDatabaseNames() without filtering to authorized databases, leaking names, transaction IDs, bootstrap fingerprints, and peer/leader topology. The flaw is reachable only when HA is enabled (arcadedb.ha.enabled=true) and the ha-raft module is loaded. An authenticated attacker with GET access to /api/v1/cluster or POST to /api/v1/cluster/bootstrap-state gains cross-database metadata disclosure. Fixed in version 26.8.1.

Affected products

  • ArcadeData ArcadeDB <= 26.7.3

Timeline

  • 2026-08-04: disclosed
  • 2026-08-18: patched: version 26.8.1

References

Related threats