ArcadeDB authorization bypass in set_server_setting MCP tool
ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool that allows authenticated read-only users to modify server configuration when allowAdmin=true. The vulnerability is fixed in version 26.8.1.
Disclosed 18 August 2026 · Record updated 13 September 2026
Impact
Any authenticated read-only user can invoke set_server_setting to modify server GlobalConfiguration, enabling configuration tampering or denial of service in MCP deployments with allowAdmin=true and non-root allowedUsers.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-75845
