PT-2026-67330 · Arcadedb · Arcadedb

·

CVE-2026-67357

·

Published

2026-08-02

·

Updated

2026-08-03

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.7.3
Description An information disclosure issue exists in the MCP get server settings tool. This flaw allows attackers with MCP access to retrieve the arcadedb.ha.clusterToken in cleartext. By using this token along with the X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers, an attacker can impersonate the root user and achieve full server compromise.
Recommendations Update to version 26.7.3 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67357
GHSA-P9WC-4FHR-78WM

Affected Products

Arcadedb