CVE-2026-67357: ArcadeDB before 26.7.3 Information Disclosure via get_server_settings
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP getserversettings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ArcadeDBto a version that resolves this vulnerability.Fixed in 26.7.3 - Compensating control
Restrict MCP access so that only trusted users/services can call the MCP get_server_settings tool, since MCP access can retrieve arcadedb.ha.clusterToken in cleartext.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67357?
The severity of CVE-2026-67357 is rated as high with a score of 7.5.
How do I fix CVE-2026-67357?
To fix CVE-2026-67357, upgrade ArcadeDB to version 26.7.3 or later.
What type of vulnerability is CVE-2026-67357?
CVE-2026-67357 is an information disclosure vulnerability.
What does CVE-2026-67357 affect?
CVE-2026-67357 affects versions of ArcadeDB prior to 26.7.3.
What information is vulnerable in CVE-2026-67357?
CVE-2026-67357 leaks the arcadedb.ha.clusterToken in cleartext through the MCP get_server_settings tool.