Information Disclosure in ArcadeDB 26.7.2 and Earlier
CVE-2026-67357

7.7HIGH

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
2 August 2026

What is CVE-2026-67357?

ArcadeDB versions before 26.7.3 have a critical flaw in the MCP get_server_settings tool that can lead to the disclosure of the arcadedb.ha.clusterToken in cleartext format. This vulnerability enables attackers with MCP access to obtain the cluster token, and with the correct headers, they can impersonate a root user and gain complete control over the server. Ensure that you update to the latest version to mitigate this security risk.

Affected Version(s)

arcadedb 0 < 26.7.3

arcadedb 26.7.3

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.