CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67340

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-08-01
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().exec() (or ProcessBuilder), achieving OS command execution when the trigger fires.

⚡ Watch CVE-2026-67340

Get an email if CVE-2026-67340 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-67340

CVE.org record

Embed the live status

CVE-2026-67340 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67340 status](https://www.csirts.com/badge/CVE-2026-67340)](https://www.csirts.com/cve/CVE-2026-67340)