PT-2026-67330 · Arcadedb · Arcadedb
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.7.3
Description
An information disclosure issue exists in the MCP
get server settings tool. This flaw allows attackers with MCP access to retrieve the arcadedb.ha.clusterToken in cleartext. By using this token along with the X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers, an attacker can impersonate the root user and achieve full server compromise.Recommendations
Update to version 26.7.3 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb