top of page
perceptive_background_267k.jpg

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-…

Published:

1 August 2026 at 22:00:00

Alert date:

2 August 2026 at 14:02:48

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Identity & Access, Zero-Day Vulnerabilities, Web Technologies

ArcadeDB versions prior to 26.7.3 contain a critical authentication bypass vulnerability in the MCP HTTP transport layer. The flaw stems from a failure to bind the authenticated principal during MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. This allows non-root MCP-allowed users to bypass all authorization controls. Attackers can exploit this to perform arbitrary database writes, execute DDL operations, perform schema mutations, and run arbitrary JavaScript code via the query tool. The vulnerability effectively grants unauthorized users elevated database privileges. A fix is available in ArcadeDB version 26.7.3 and later. The issue is tracked as CVE-2026-68578 and has been disclosed via GitHub Security Advisories and VulnCheck.

Technical details

Mitigation steps:

Affected products:

ArcadeDB

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page