Junglewise Threat Intelligence

CVE-2026-75852: ArcadeDB MongoDB wire protocol authentication bypass

CVE-2026-75852 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: ArcadeData ArcadeDB. Vendors: ArcadeData.

Executive brief

ArcadeDB is a multi-model database engine that includes a MongoDB compatibility layer. The MongoDB wire-protocol plugin fails to enforce authentication on database commands, allowing unauthenticated attackers to read, modify, or delete data from any database by connecting directly to port 27017 without credentials. This represents a complete compromise of data confidentiality, integrity, and availability for all databases on the affected instance.

Technical details

The vulnerability is a missing authentication enforcement (CWE-306) and missing authorization check (CWE-862) in ArcadeDB's MongoDB wire-protocol plugin. The handleCommand method in MongoDBBackend.java only validates SASL authentication for saslStart and saslContinue operations; all data commands (insert, find, update, delete, create) bypass authentication and pass directly to the parent handler. Additionally, no authenticated user state is bound to the connection, so all ACLs are disabled. An unauthenticated network attacker can connect to port 27017 and issue arbitrary data commands against any database without credentials. The vulnerability affects versions up to and including 26.7.3; patch version 26.8.1 is available.

Affected products

  • ArcadeData ArcadeDB before 26.8.1

Timeline

  • 2026-08-04: disclosed
  • 2026-08-18: patched: Version 26.8.1 released

References

Related threats