---
id: CVE-2026-75842
title: >-
  ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability
  in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read
  local files
summary: >-
  ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability
  in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read
  local files. Attackers with read query privileges can use the file:// protocol
  in…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-08-18'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75842'
references:
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-hfp5-6gcp-8c75
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/arcadedb-before-arbitrary-file-read-via-load-csv
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-hfp5-6gcp-8c75
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0046
epssPercentile: 0.37134
ingestedAt: '2026-09-08T21:11:12.280Z'
---

## Overview

ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in LOAD CSV statements to access arbitrary files with server process privileges, exfiltrating sensitive data directly in query responses.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
