CyberRota Analysis
AI-GeneratedArcadeDB versions prior to 26.8.1 are vulnerable due to a missing authentication flaw in the Redis wire-protocol plugin, enabling unauthenticated attackers to read, write, and delete data. This critical vulnerability allows attackers to connect to the Redis port and execute arbitrary commands on any database, effectively bypassing security measures. Organizations using affected versions should prioritize immediate updates to mitigate potential data breaches and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on the server without providing credentials, bypassing all security gates.