CVE-2026-68578
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
02/08/2026
Last modified:
02/08/2026
Description
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH



