Authentication Bypass in ArcadeDB by New Generation Data Systems
CVE-2026-68578

7.7HIGH

Key Information:

Vendor

Arcadedata

Status
Vendor
CVE Published:
2 August 2026

What is CVE-2026-68578?

ArcadeDB versions prior to 26.7.3 exhibit a serious flaw in the MCP HTTP transport, where the authentication of the principal is not sufficiently enforced. This vulnerability enables users with non-root MCP permissions to bypass necessary permission checks, allowing them to execute arbitrary database operations, including schema mutations and JavaScript execution through the query tool. The lack of rigorous principal binding poses significant risks to data integrity and security.

Affected Version(s)

arcadedb 0 < 26.7.3

arcadedb 26.7.3

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.