CVE-2026-54077 PUBLISHED

ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users

Assigner: GitHub_M
Reserved: 11.06.2026 Published: 15.09.2026 Updated: 15.09.2026

ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java without validation. An authenticated user with SQL command access through /api/v1/command or /api/v1/query can supply HTTP or HTTPS destinations to make server-side requests to internal services, or file:// paths to read files accessible to the server process and ingest the results as queryable records. The XML importer also permits DTD processing and external entities, enabling entity expansion. The root-only /api/v1/server administration endpoint is not affected. The fix requires updateSecurity permission, blocks local-network import destinations by default through arcadedb.server.security.importBlockLocalNetworks, supports the arcadedb.server.security.importAllowedLocalPaths file allow-list, and disables XML DTD processing and external entities. This issue is fixed in version 26.6.1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
CVSS Score: 7.1

Product Status

Vendor ArcadeData
Product arcadedb
Versions
  • Version < 26.6.1 is affected
Vendor com.arcadedb
Product arcadedb-engine
Versions
  • Version < 26.6.1 is affected

References

Problem Types

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE
  • CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') CWE
  • CWE-918: Server-Side Request Forgery (SSRF) CWE