Description
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.
Severity (CVSS)
| Base score | 7.7 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-306 — Missing Authentication for Critical Function
Affected products
| Vendor | Product | Versions |
|---|---|---|
| ArcadeData | arcadedb | 0 to <26.7.3; 26.7.3 |
References
- https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-6x73-v3rc-f57c (vendor-advisory)
- https://www.vulncheck.com/advisories/arcadedb-authentication-bypass-via-mcp-transport (third-party-advisory)
Generated from the official CVE List on 03 Aug 2026 08:53 UTC.