---
id: CVE-2026-93597
title: >-
  ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in
  the SSRF guard used by IMPORT DATABASE and server commands
summary: >-
  ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in
  the SSRF guard used by IMPORT DATABASE and server commands. Authenticated
  attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses
  embedding RFC…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: ArcadeData
product: arcadedb
affected:
  - arcadedb < 26.9.1
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:18:29.630'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93597'
references:
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-67m7-7w7g-mpmh
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/arcadedb-before-26.9.1-ssrf-via-ipv6-transition-addresses
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-67m7-7w7g-mpmh
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T17:55:20.933260Z'
ingestedAt: '2026-09-18T13:41:41.664Z'
epss: 0.00334
epssPercentile: 0.26935
---

## Overview

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or loopback IPv4 payloads to reach internal services and cloud metadata endpoints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
