CVE-2026-67357
published 2026-08-02CVE-2026-67357: ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in…
PriorityP346high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.25%
16.7th percentile
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arcadedata | arcadedb | < 26.7.3 | 26.7.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ArcadeData ArcadeDB up to 26.7.2 MCP get_server_settings information disclosure (EUVD-2026-51987)
vuldb·2026-08-02·CVSS 7.5
CVE-2026-67357 [HIGH] ArcadeData ArcadeDB up to 26.7.2 MCP get_server_settings information disclosure (EUVD-2026-51987)
A vulnerability was found in ArcadeData ArcadeDB up to 26.7.2. It has been declared as problematic. This issue affects the function get_server_settings of the component MCP. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-67357. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext.
ghsa_unreviewed·2026-08-02
CVE-2026-67357 [HIGH] CWE-200 ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext.
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-02
Published