Heimdall Data Database Proxy Vulnerable to RCE via Directory Traversal
A directory traversal vulnerability in Heimdall Data Database Proxy allows authenticated remote attackers to achieve arbitrary code execution.

A critical vulnerability has been disclosed in Heimdall Data Database Proxy, a software solution designed to manage and proxy database connections. The flaw, identified as ZDI-26-479 and assigned CVE-2026-18274, allows authenticated remote attackers to execute arbitrary code on affected systems.
The vulnerability stems from an improper validation of user-supplied path information within the uploadJar method. This oversight enables attackers who have already gained authenticated access to the proxy to exploit a directory traversal weakness. By carefully crafting a request, an attacker can manipulate the file path to upload arbitrary JAR files to unintended locations on the server.
Successful exploitation of this flaw could lead to remote code execution (RCE) in the context of the root user. This level of access would grant an attacker complete control over the compromised server, allowing them to install malicious software, steal sensitive data, disrupt operations, or use the server as a pivot point for further network intrusions.
The Zero Day Initiative (ZDI), which coordinated the disclosure, assigned the vulnerability a CVSS score of 7.2, classifying it as high severity. The vulnerability requires authentication, meaning an attacker must first compromise legitimate user credentials or exploit another vulnerability to gain access before they can leverage this RCE flaw.
Heimdall Data has addressed this vulnerability by releasing a patch in build 25.03.01.24. Users of Heimdall Data Database Proxy are strongly advised to update to this latest version as soon as possible to mitigate the risk of exploitation.
The vulnerability was reported to the vendor on April 14, 2026, and the coordinated public release of the advisory occurred on July 29, 2026. The advisory was updated on the same day. The discovery and reporting of this vulnerability are credited to Do Quoc Anh from mbbank.com.vn.