


Perceptive Security
SOC/SIEM Consultancy

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-…
Published:
1 August 2026 at 22:00:00
Alert date:
2 August 2026 at 14:02:48
Source:
nvd.nist.gov
Database & Storage, Identity & Access, Zero-Day Vulnerabilities, Web Technologies
ArcadeDB versions prior to 26.7.3 contain a critical authentication bypass vulnerability in the MCP HTTP transport layer. The flaw stems from a failure to bind the authenticated principal during MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. This allows non-root MCP-allowed users to bypass all authorization controls. Attackers can exploit this to perform arbitrary database writes, execute DDL operations, perform schema mutations, and run arbitrary JavaScript code via the query tool. The vulnerability effectively grants unauthorized users elevated database privileges. A fix is available in ArcadeDB version 26.7.3 and later. The issue is tracked as CVE-2026-68578 and has been disclosed via GitHub Security Advisories and VulnCheck.
Technical details
Mitigation steps:
Affected products:
ArcadeDB
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-68578
https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-6x73-v3rc-f57c
https://www.vulncheck.com/advisories/arcadedb-authentication-bypass-via-mcp-transport
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
