CVE-2026-68578 Details
Description
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.
A vulnerability exists in ArcadeDB versions prior to 26.7.3, where the MCP (Model Context Protocol) HTTP transport fails to bind the authenticated user, leading to a bypass of all permission checks. This flaw allows non-root users with MCP access to perform unrestricted database writes, DDL operations, schema changes, and execute arbitrary JavaScript code through the query tool.
Users should update to ArcadeDB version 26.7.3 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 2, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-6x73-v3rc-f57c | CISA-ADP | AdvisoryTechnical AnalysisVendor |
| https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-6x73-v3rc-f57c | [email protected] | AdvisoryTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/arcadedb-authentication-bypass-via-mcp-transport | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ArcadeDB | <= 26.7.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 2, 2026 | New CVE Received | [email protected] |
Volerion