Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xgx7-2w7q-r9mc

Опубликовано: 18 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.

ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-306

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-306