What is CVE-2026-67357?
ArcadeDB versions prior to 26.7.3 contain an information disclosure vulnerability in the MCP 'get_server_settings' tool that leaks the 'arcadedb.ha.clusterToken' in cleartext. Attackers with MCP access can retrieve the cluster token and potentially misuse it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers. Upgrading to version 26.7.3 is recommended.
Azərbaycanca: ArcadeDB-nin 26.7.3-dən əvvəlki versiyalarında MCP 'get_server_settings' aləti vasitəsilə 'arcadedb.ha.clusterToken' məxfi məlumatı cleartext olaraq sızdıran informasiya ifşası zəifliyi aşkar edilib. Bu, MCP girişi olan hücumçulara klaster tokeni əldə edib X-ArcadeDB-Cluster-Token və X-ArcadeDB-Forwarded-User başlıqları ilə sui-istifadə etməyə imkan verir. ArcadeDB-ni 26.7.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ1
What secret does CVE-2026-67357 expose?
This vulnerability leaks the 'arcadedb.ha.clusterToken' in cleartext through ArcadeDB's 'get_server_settings' MCP tool.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.