CRITICALVulnerability

CVE-2026-75843

ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a transaction ID to run unrestricted JavaScript that creates server-wide administrator accounts.

Properties

severity
CRITICAL
score
9.9
epss_score
0.00303
cve_id
CVE-2026-75843
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-18T12:19:34.740
last_modified
2026-08-31T20:33:07.713
epss_percentile
0.22554

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Privilege Management

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75843 — Ninja Signal Threat Intelligence | Ninja Signal