Skip to content

Critical ArangoDB Flaws Allow Authentication Bypass and Remote Code Execution as Root

Cybersecuritynews Tushar Subhra Dutta September 9, 2026

Two critical flaws in ArangoDB can let an outsider bypass login controls, read or alter database data, and then gain root-level code execution on the underlying host. The issues affect installations through version 3.12.10.1, creating serious risk for internet-facing databases and container deployments. The attack does not rely on stolen passwords, a user click, or […]

Extracted Entities