SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-67357

HIGH · CVSS 7.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

ArcadeDB versions prior to 26.7.3 are vulnerable to an information disclosure flaw in the MCP get_server_settings tool, which exposes the arcadedb.ha.clusterToken in cleartext. Attackers with access to the MCP can exploit this vulnerability to retrieve the cluster token, enabling them to impersonate root and potentially achieve full server compromise. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and control over their database systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67357
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.