Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

ArcadeDB authorization bypass in set_server_setting MCP tool

ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool that allows authenticated read-only users to modify server configuration when allowAdmin=true. The vulnerability is fixed in version 26.8.1.

Disclosed 18 August 2026 · Record updated 13 September 2026

Impact

Any authenticated read-only user can invoke set_server_setting to modify server GlobalConfiguration, enabling configuration tampering or denial of service in MCP deployments with allowAdmin=true and non-root allowedUsers.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-75845