CyberRota Analysis
AI-GeneratedArcadeDB versions prior to 26.7.3 are vulnerable to an information disclosure flaw in the MCP get_server_settings tool, which exposes the arcadedb.ha.clusterToken in cleartext. Attackers with access to the MCP can exploit this vulnerability to retrieve the cluster token, enabling them to impersonate root and potentially achieve full server compromise. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and control over their database systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.