7.7highHigh
CVE-2026-75842
ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in LOAD CSV statements to access arbitrary files with server process privileges, exfiltrating sensitive data directly in query responses.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an ordinary user account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.7 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N- CVSS v4
- 8.3
- Weakness
- CWE-22
- Assigned by
- disclosure@vulncheck.com
Dates
- Published
- 2026-08-18
- Last modified
- 2026-09-08
- Sources
- NVD