Junglewise Threat Intelligence

CVE-2026-68578: ArcadeDB MCP HTTP transport authentication bypass

CVE-2026-68578 · Severity: high · CVSS 7.5 · Published 2026-08-02

Technologies: ArcadeData ArcadeDB. Vendors: ArcadeData.

Executive brief

ArcadeDB is a NoSQL database platform that supports multiple command transports including an MCP (Model Context Protocol) HTTP interface. A flaw in the MCP transport fails to bind the authenticated user to the request context, causing all permission checks to be silently skipped. An attacker with any non-root MCP access can perform unrestricted database modifications, schema changes, security updates, and arbitrary code execution.

Technical details

The vulnerability is an authentication bypass (CWE-306) in ArcadeDB's MCP HTTP transport layer (MCPHttpHandler). While all other transports (Bolt, Postgres, gRPC, HTTP-DatabaseAbstractHandler) properly bind the authenticated principal via setCurrentUser() before executing commands, the MCP transport omits this critical step. The engine's permission checks in LocalDatabase deliberately no-op when no user is bound, effectively disabling all authorization gates. An attacker with MCP-allowed credentials can exploit this via the query tool with JavaScript language to achieve arbitrary code execution and persistence: the PolyglotQueryEngine eagerly evaluates the script before idempotent checks, allowing database.command() calls to bypass UPDATE_SECURITY and other gates. Exploitation requires MCP to be enabled (default: disabled) and the attacker to be in allowedUsers (default: ["root"]). The fix, available in 26.7.3, binds the principal in MCPToolUtils by calling DatabaseContext.setCurrentUser() before tool execution and clearing it in a finally block.

Affected products

  • ArcadeData ArcadeDB before 26.7.3

Timeline

  • 2026-07-17: disclosed: GitHub Security Advisory GHSA-6x73-v3rc-f57c published
  • 2026-07-17: patched: Version 26.7.3 released with fix
  • 2026-08-02: advisory: NVD CVE-2026-68578 entry published

References

Related threats