{"id":"GHSA-48qw-824m-86pr","summary":"ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read","details":"### Impact\n\nA user holding only `reader` (read-only) privileges on a single database could execute arbitrary JVM code by sending a `\"language\": \"js\"` command to the `POST /api/v1/command/{database}` HTTP endpoint, and use it to read arbitrary files on the host filesystem (e.g. `/etc/passwd`, configuration files), outside the scope of the database itself.\n\nTwo cooperating defects made this possible:\n\n1. **Missing authorization on the scripting path (CWE-863 / CWE-269).** Polyglot script execution (`js` and other GraalVM languages) never went through the database authorization checks applied to SQL/Cypher, so any authenticated principal - regardless of database role - could run scripts.\n2. **Sandbox whitelist bypass.** The GraalVM sandbox restricts direct class lookups to a configured `allowedPackages` list, but a script could reach arbitrary classes by reflecting off the bound `database` object: `database.getClass().getClassLoader().loadClass(\"java.io.File\")`.\n\nProcess creation was already blocked (`allowCreateProcess(false)`), so the confirmed impact is host **file read**, not OS command execution. Confidentiality: High. Integrity/Availability: None.\n\nThis is a distinct entry point and root cause from CVE-2026-44221, CVE-2026-54076 and CVE-2026-54077, and is reproducible on builds that already contain those fixes.\n\n### Patches\n\nThe fix is applied in the engine so it covers every entry point (HTTP command, HA-forwarded commands, MCP `analyze`), not only the HTTP handler:\n\n- Polyglot script execution now requires the `updateSecurity` database-administrator permission on `command`, `analyze` and `registerFunctions`. The check runs on the request thread that carries the authenticated user and is a no-op in embedded mode and internal/system contexts (schema load, HA replication apply).\n- The GraalVM host-access policy now denies access to `java.lang.Class`, `java.lang.ClassLoader` and `java.lang.reflect` members, closing the reflection escape that bypassed `allowedPackages` - even for authorized administrators - while leaving normal method calls on bound objects and explicit `Java.type(...)` lookups (governed by `allowedPackages`) working.\n\n### Workarounds\n\nUntil upgraded, do not grant command/query access on the HTTP API to untrusted users, and treat any account that can reach `/api/v1/command` as capable of code execution. Note that after the fix, non-administrator accounts can no longer run `js`/polyglot scripts over HTTP.\n\n### Credit\n\nReported by @kyojune76.","aliases":["CVE-2026-65831"],"modified":"2026-09-16T03:56:06.395820071Z","published":"2026-07-16T20:13:20Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-269","CWE-863"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-16T20:13:20Z"},"references":[{"type":"WEB","url":"https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-48qw-824m-86pr"},{"type":"PACKAGE","url":"https://github.com/ArcadeData/arcadedb"},{"type":"WEB","url":"https://github.com/ArcadeData/arcadedb/releases/tag/26.7.1"}],"affected":[{"package":{"name":"com.arcadedb:arcadedb-server","ecosystem":"Maven","purl":"pkg:maven/com.arcadedb/arcadedb-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.7.1"}]}],"versions":["21.10.1","21.10.2","21.11.1","21.12.1","21.9.1","21.9.1-beta","22.1.1","22.1.2","22.1.3","22.10.1","22.11.1","22.12.1","22.2.1","22.8.1","22.9.1","23.1.1","23.1.2","23.10.1","23.11.1","23.12.1","23.12.2","23.2.1","23.3.1","23.4.1","23.5.1","23.6.1","23.7.1","23.9.1","24.1.1","24.10.1","24.11.1","24.11.2","24.2.1","24.4.1","24.5.1","24.6.1","25.1.1","25.10.1","25.11.1","25.12.1","25.2.1","25.3.1","25.3.2","25.4.1","25.5.1","25.6.1","25.7.1","25.8.1","25.9.1","26.1.1","26.2.1","26.2.2","26.3.1","26.3.2","26.4.2","26.5.1","26.6.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-48qw-824m-86pr/GHSA-48qw-824m-86pr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}