---
id: CVE-2026-75854
title: >-
  ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability
  in the Redis wire-protocol plugin that allows unauthenticated attackers to
  read, write, and delete data
summary: >-
  ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability
  in the Redis wire-protocol plugin that allows unauthenticated attackers to
  read, write, and delete data. Attackers can connect to the Redis port and
  execute a…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
published: '2026-08-18'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75854'
references:
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-m46c-jh3x-xwrp
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/arcadedb-redis-wire-protocol-plugin-missing-authentication
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-m46c-jh3x-xwrp
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00887
epssPercentile: 0.57584
ingestedAt: '2026-09-08T21:11:12.280Z'
---

## Overview

ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on the server without providing credentials, bypassing all security gates.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
