Junglewise Threat Intelligence

CVE-2026-75843: ArcadeDB gRPC transaction privilege escalation via authentication bypass

CVE-2026-75843 · Severity: critical · CVSS 9.9 · Published 2026-08-18

Technologies: ArcadeData ArcadeDB. Vendors: ArcadeData.

Executive brief

ArcadeDB is a distributed database platform that supports JavaScript scripting and role-based access control. A flaw in the gRPC transaction handler allows any authenticated reader to bypass scripting authorization checks and execute unrestricted JavaScript code, enabling attackers to create server-wide administrator accounts and achieve full system compromise equivalent to remote code execution.

Technical details

ArcadeDB's gRPC service fails to bind the authenticated principal (via setCurrentUser) when creating a dedicated single-thread executor for external transactions in the beginTransaction method (ArcadeDbGrpcService.java:1468-1476). When executeCommand is invoked with a transaction ID, it dispatches the command onto this executor thread where the current user context remains null. The scripting authorization gate in LocalDatabase.java:721-723 performs an early-return check that is ineffective on null users, allowing JavaScript commands to execute without UPDATE_SECURITY permission checks. An authenticated reader (low privileges) can call BeginTransaction to obtain a transaction ID, then invoke ExecuteCommand with language="js" to execute arbitrary JavaScript—for example, calling database.getSecurity().createUser() to create a server-wide administrator account. The gRPC plugin is enabled by default and shipped in the standard distribution. Patched in version 26.8.1.

Affected products

  • ArcadeData ArcadeDB before 26.8.1

Timeline

  • 2026-08-04: disclosed
  • 2026-08-18: advisory

References

Related threats