Description
ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated users' browsers.
Published: 2026-02-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Arangodb
Arangodb arangodb Community Edition
Vendors & Products Arangodb
Arangodb arangodb Community Edition

Sun, 15 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
Description ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated users' browsers.
Title ArangoDB Community Edition 3.4.2-1 XSS via aardvark admin interface
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Arangodb Arangodb Community Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-17T20:10:05.901Z

Reserved: 2026-02-15T13:04:29.728Z

Link: CVE-2019-25367

cve-icon Vulnrichment

Updated: 2026-02-17T20:10:00.706Z

cve-icon NVD

Status : Deferred

Published: 2026-02-15T14:16:05.083

Modified: 2026-04-15T00:35:42.020

Link: CVE-2019-25367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-16T09:43:02Z

Weaknesses