CVE-2026-75842: ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV

Published Aug 18, 2026
·
Updated

ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in LOAD CSV statements to access arbitrary files with server process privileges, exfiltrating sensitive data directly in query responses.

Affected Software

1 affected component
ArcadeDB ArcadeDB<26.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ArcadeDB to a version that resolves this vulnerability.

    Fixed in 26.8.1
  2. Compensating control

    Restrict/limit who has read query privileges so only fully trusted authenticated users can execute OpenCypher queries that include the LOAD CSV FROM clause (to prevent use of the file:// protocol for arbitrary file reads).

Event History

Aug 18, 2026
CVE Published
via MITRE·11:19 AM
Data Sourced
via MITRE·11:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments and users are exposed?

ArcadeDB deployments running versions before 26.8.1 are affected when authenticated users have read query privileges. The exposed files are those readable by the ArcadeDB server process, rather than only files owned by the querying user.

2

What access is required to exploit this issue?

An attacker needs valid authentication and read query privileges, but does not need user interaction. They can issue OpenCypher LOAD CSV statements using the file:// protocol and receive file contents in query responses.

3

What remediation is identified?

Upgrade ArcadeDB to version 26.8.1 or later. The provided information does not identify an alternative mitigation for environments where upgrading cannot occur immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203