---
id: CVE-2026-75840
title: >-
  ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the
  GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular
  expressions to validate package names
summary: >-
  ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the
  GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular
  expressions to validate package names. Attackers with trigger creation
  privileges …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-1025
published: '2026-08-18'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75840'
references:
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-wx28-2265-f788
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/arcadedb-before-arbitrary-file-read-via-unescaped-regex
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-wx28-2265-f788
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00397
epssPercentile: 0.3379
ingestedAt: '2026-09-08T21:11:12.280Z'
---

## Overview

ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. Attackers with trigger creation privileges can use Java.type() to access java.util.zip.ZipFile or java.util.jar.JarFile classes and read arbitrary files on the host system as the ArcadeDB server process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
