Security Advisory

CVE-2026-75845

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-18 11:19:52
Last updated 2026-08-18 15:12:23
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSettingTool.execute() gates only on the global allowAdmin flag and never checks the caller's role, so in an MCP deployment with allowAdmin=true and a non-root allowedUsers set, any authenticated read-only user can invoke set_server_setting to modify server GlobalConfiguration, enabling configuration tampering or denial of service. The issue is fixed in 26.8.1.