Improper Token Redaction in ArcadeDB by ArcadeData
CVE-2026-67343

8.7HIGH

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67343?

ArcadeDB versions prior to 26.7.2 contain a vulnerability that fails to redact the cluster token when accessed via the GET /api/v1/server endpoint. This allows authenticated users to view the sensitive arcadedb.ha.clusterToken in plaintext. With this exposed token, attackers can craft requests using the X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate an administrative user, enabling them to perform critical operations like user creation, database manipulations, and server shutdown, thereby compromising the integrity and security of the system.

Affected Version(s)

arcadedb 0 < 26.7.2

arcadedb 26.7.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.