ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. Attackers with trigger creation privileges can use Java.type() to access java.util.zip.ZipFile or java.util.jar.JarFile classes and read arbitrary files on the host system as the ArcadeDB server process.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
ArcadeDB versions prior to 26.8.1 suffer from a critical sandbox escape vulnerability in their GraalVM JavaScript execution environment. The flaw stems from improper validation of package names using unescaped regular expressions in the allowlist enforcement mechanism, creating a gap that skilled attackers can exploit. Users with trigger creation privileges can leverage Java.type() to instantiate restricted classes like java.util.zip.ZipFile and java.util.jar.JarFile, gaining the ability to read arbitrary files from the host system with the privileges of the ArcadeDB server process. This vulnerability affects database administrators, application developers using ArcadeDB for data processing, and organizations running ArcadeDB in production environments where trigger functionality is enabled.
While this CVE currently maps to zero MITRE ATT&CK techniques in standard frameworks, Casky's Claude-powered analysis would correlate this attack pattern with Privilege Escalation (T1548) and Defense Evasion (T1562) techniques, as attackers bypass sandbox restrictions to gain unauthorized system access. Practitioners using Casky would observe findings flagged around suspicious Java reflection patterns, unexpected filesystem access attempts from database processes, and trigger definitions containing Java.type() calls accessing java.io or java.util.zip classes. The extended reasoning capability would identify the logical chain: trigger creation → GraalVM sandbox → regex bypass → unrestricted class instantiation → file system access, enabling security teams to detect this exploitation pattern before sensitive data exfiltration occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-75840. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation