Executive brief
ArcadeDB is a distributed database platform that supports JavaScript scripting and role-based access control. A flaw in the gRPC transaction handler allows any authenticated reader to bypass scripting authorization checks and execute unrestricted JavaScript code, enabling attackers to create server-wide administrator accounts and achieve full system compromise equivalent to remote code execution.
Technical details
ArcadeDB's gRPC service fails to bind the authenticated principal (via setCurrentUser) when creating a dedicated single-thread executor for external transactions in the beginTransaction method (ArcadeDbGrpcService.java:1468-1476). When executeCommand is invoked with a transaction ID, it dispatches the command onto this executor thread where the current user context remains null. The scripting authorization gate in LocalDatabase.java:721-723 performs an early-return check that is ineffective on null users, allowing JavaScript commands to execute without UPDATE_SECURITY permission checks. An authenticated reader (low privileges) can call BeginTransaction to obtain a transaction ID, then invoke ExecuteCommand with language="js" to execute arbitrary JavaScript—for example, calling database.getSecurity().createUser() to create a server-wide administrator account. The gRPC plugin is enabled by default and shipped in the standard distribution. Patched in version 26.8.1.
Affected products
- ArcadeData ArcadeDB before 26.8.1
Timeline
- 2026-08-04: disclosed
- 2026-08-18: advisory