Improper Token Redaction in ArcadeDB by ArcadeData
CVE-2026-67343
8.7HIGH
What is CVE-2026-67343?
ArcadeDB versions prior to 26.7.2 contain a vulnerability that fails to redact the cluster token when accessed via the GET /api/v1/server endpoint. This allows authenticated users to view the sensitive arcadedb.ha.clusterToken in plaintext. With this exposed token, attackers can craft requests using the X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate an administrative user, enabling them to perform critical operations like user creation, database manipulations, and server shutdown, thereby compromising the integrity and security of the system.
Affected Version(s)
arcadedb 0 < 26.7.2
arcadedb 26.7.2
