Information Disclosure in ArcadeDB 26.7.2 and Earlier
CVE-2026-67357
7.7HIGH
What is CVE-2026-67357?
ArcadeDB versions before 26.7.3 have a critical flaw in the MCP get_server_settings tool that can lead to the disclosure of the arcadedb.ha.clusterToken in cleartext format. This vulnerability enables attackers with MCP access to obtain the cluster token, and with the correct headers, they can impersonate a root user and gain complete control over the server. Ensure that you update to the latest version to mitigate this security risk.
Affected Version(s)
arcadedb 0 < 26.7.3
arcadedb 26.7.3
