# CVE-2026-65831

## Summary

- **CVE ID:** CVE-2026-65831
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-269, CWE-863
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions do not enforce database-administrator authorization. GraalPolyglotEngine also permits scripts to bypass the allowedPackages whitelist by reflecting from the bound database object through database.getClass().getClassLoader().loadClass to arbitrary host classes. These cooperating defects allow a read-only database user to read arbitrary host files outside the database scope. Process creation is already blocked, so OS command execution is not confirmed. The issue is distinct from CVE-2026-44221, CVE-2026-54076, and CVE-2026-54077. This issue is fixed in version 26.7.1.

## Affected Products

- ArcadeData — arcadedb (< 26.7.1)
- com.arcadedb — arcadedb-server (< 26.7.1)

## References

- [CNA](https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-48qw-824m-86pr)
- [CNA](https://github.com/ArcadeData/arcadedb/commit/8ca396c07e471a0b97fee075eeb956b5e24a23be)
- [CNA](https://github.com/ArcadeData/arcadedb/releases/tag/26.7.1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 37.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._