CVE-2026-68578
Received Received - Intake

ArcadeDB MCP HTTP Transport Authentication Bypass Leading to Arbitrary Code Execution

Vulnerability report for CVE-2026-68578, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: VulnCheck

Description

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arcadedb arcadedb to 26.7.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ArcadeDB versions before 26.7.3 have a flaw where the authenticated user's principal is not properly bound in the MCP HTTP transport. This causes permission checks to fail silently, allowing non-root users with MCP privileges to bypass security restrictions.

Impact Analysis

Non-root users with MCP access can perform unauthorized actions like writing to databases, modifying schemas, executing DDL commands, and running arbitrary JavaScript code through the query tool. This could lead to data theft, corruption, or system compromise.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to sensitive data, leading to potential breaches of GDPR (data protection) or HIPAA (health information privacy). Unauthorized modifications or exfiltration of data would be non-compliant with these regulations.

Mitigation Strategies

Upgrade ArcadeDB to version 26.7.3 or later to address the authentication bypass issue. Ensure non-root MCP users are restricted from executing privileged operations until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68578. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart