


Perceptive Security
SOC/SIEM Consultancy

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in c…
Published:
1 August 2026 at 22:00:00
Alert date:
2 August 2026 at 14:02:48
Source:
nvd.nist.gov
Database & Storage, Identity & Access, Web Technologies
ArcadeDB versions prior to 26.7.3 contain a critical information disclosure vulnerability in the MCP get_server_settings tool. The tool leaks the arcadedb.ha.clusterToken in cleartext, exposing a sensitive cluster authentication secret. Attackers with MCP access can retrieve this token and use it alongside X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User HTTP headers to impersonate the root user. This allows full server compromise without requiring valid credentials. The vulnerability is tracked as CVE-2026-67357 and has been patched in ArcadeDB version 26.7.3. Multiple advisories have been published including from GitHub Security Advisories and VulnCheck.
Technical details
Mitigation steps:
Affected products:
ArcadeDB
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67357
https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-p9wc-4fhr-78wm
https://www.vulncheck.com/advisories/arcadedb-information-disclosure-via-get-server-settings
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
