Junglewise Threat Intelligence

CVE-2026-67343: ArcadeDB cluster token disclosure in GET /api/v1/server

CVE-2026-67343 · Severity: high · CVSS 8.8 · Published 2026-08-01

Technologies: ArcadeData ArcadeDB. Vendors: ArcadeData.

Executive brief

ArcadeDB is a database platform used for storing and managing application data. Versions before 26.7.2 expose a sensitive authentication token through an API endpoint that should have been hidden, allowing any authenticated user to read the token in plain text. An attacker with basic user access can use this token to impersonate the administrative root account, gaining the ability to create users, delete databases, and shut down the server entirely.

Technical details

The vulnerability is an information disclosure flaw (CWE-200) in the GET /api/v1/server endpoint. The root cause is that the exportSettings() function in GetServerHandler.java fails to apply the isHidden() predicate to all sensitive configuration keys; it masks only keys containing "password" by name, ignoring the arcadedb.ha.clusterToken which is explicitly flagged as hidden. A separate authentication bypass allows requests bearing X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to bypass password checks in validateClusterForwardedAuth(), granting access as the specified user. Attack requires only authentication (no root privilege), network reachability to the API, and is triggered when an operator has explicitly configured HA_CLUSTER_TOKEN (auto-generated defaults are not affected). Exploitation yields full server compromise. Patched in version 26.7.2.

Affected products

  • ArcadeData ArcadeDB before 26.7.2

Timeline

  • 2026-07-09: disclosed
  • 2026-08-01: advisory
  • 2026-07-09: patched: Version 26.7.2 released

References

Related threats