Vulnerability Description
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().exec() (or ProcessBuilder), achieving OS command execution when the trigger fires.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-x9f9-r4m8-9xc2
- https://www.vulncheck.com/advisories/arcadedb-before-remote-code-execution-via-t
FAQ
What is CVE-2026-67340?
CVE-2026-67340 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authen...
How severe is CVE-2026-67340?
CVE-2026-67340 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-67340?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.