ThreatCluster

Critical ArangoDB Vulnerabilities Enable Remote Code Execution and Data Access

First seen 9 Sep 2026, 18:13 UTC GbhackersCybersecuritynews 61

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities in ArangoDB were reported on August 23, 2026, allowing unauthenticated attackers to bypass authentication and gain access to protected database APIs. Once access is obtained, attackers can escalate privileges to execute code as root on affected hosts. The vulnerabilities impact all installations up to version 3.12.10.1, posing a significant risk for internet-facing databases and container deployments. Patches were released on August 31, 2026, and GitHub Security Advisories were published on September 6, 2026. The flaws do not require stolen passwords or user interaction for exploitation. Security researchers have emphasized the urgency of applying the patches to mitigate risks. Organizations using affected versions are advised to update immediately to prevent potential breaches.

Key Points: • Two critical vulnerabilities in ArangoDB allow authentication bypass and remote code execution. • Affected versions include all installations up to 3.12.10.1, posing risks for internet-facing databases. • Patches were released on August 31, 2026, with advisories published on September 6, 2026.

Ask AI about this cluster

Timeline

2026-08-23
Vulnerabilities reported to ArangoDB
Security researchers disclosed two critical vulnerabilities that allow unauthenticated access and privilege escalation.
Gbhackers
2026-08-31
Patches released
ArangoDB released patches to address the critical vulnerabilities affecting all installations up to version 3.12.10.1.
Gbhackers
2026-09-06
GitHub Security Advisories published
Advisories GHSA-rrgq-978q-36mq were published to inform users about the vulnerabilities and patches.
Gbhackers