CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-75843 — ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC tra...

·Source: NIST NVD

Updated:

Executive Summary

ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a transaction ID to run unrestricted JavaScript that creates server-wide administrator accounts.

Analysis

ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a transaction ID to run unrestricted JavaScript that creates server-wide administrator accounts. CVSS Score: 9.9. Published: 2026-08-18T12:19:34.740.

Indicators of Compromise (1)

CVE (1)
CVE-2026-75843
Source Attribution

Originally published by NIST NVD on Aug 18, 2026. Verified by: NIST.

Related Threats