CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-67340

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
0.52%
41th pct
KEV
No
Class
oss containerizable
CWE-94

Description

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().exec() (or ProcessBuilder), achieving OS command execution when the trigger fires.

Affected packages

Maven com.arcadedb:arcadedb-engine 0 → 26.7.2

References

Status: profiled · ingested 2026-08-03T18:00:54.000Z