Impact
ArcadeDB versions before 26.7.3 contain an information disclosure flaw in the MCP get_server_settings tool. The flaw exposes the arcadedb.ha.clusterToken in cleartext, allowing an attacker with MCP access to capture the cluster token. With this token, the attacker can construct HTTP requests using X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate the root user and fully compromise the server, leading to unauthorized control of the database and any data stored within.
Affected Systems
ArcadeData's ArcadeDB database engine, versions prior to 26.7.3, are affected by this vulnerability. Only deployments using those earlier releases are at risk; newer versions (26.7.3 and later) are considered secure.
Risk and Exploitability
The CVSS score of 7.7 categorizes the issue as high severity. Exploitation requires prior MCP access, which is usually limited to administrators, but once obtained the token can be reused across the cluster. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, yet its potential for full server compromise warrants close monitoring and timely patching by administrators.
OpenCVE Enrichment