CVE-2026-67357Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-02); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-02: 2Mentions · 2026-09-13: 1Technical Details · 2026-08-02: 208-0209-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Ryx@PadhiyarRushi

    ArcadeDB MCP had a settings tool that just returned the high-availability cluster token in cleartext (CVE-2026-67357). That token was enough to impersonate root through specific headers. Authenticated MCP client → cluster-level access. “Settings” endpoints that dump secrets are still one of the most reliable privilege pivots in new protocols. https://adversa.ai/blog/top-mcp-security-resources-september-2026/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec

    00011110
    668 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-67357 ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in clearte… https://www.cve.org/CVERecord?id=CVE-2026-67357

    Post summary

    The statement informs that ArcadeDB versions prior to 26.7.3 contain an information‑disclosure flaw that leaks the cluster token via get_server_settings, with no evidence of active exploitation, PoC, or patch.

    00000649
    57.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-67357 Information Disclosure and Root Impersonation in ArcadeDB Before 26.7.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-67357

    Post summary

    A brief notice that CVE-2026-67357, an Information Disclosure and Root Impersonation vulnerability, exists in ArcadeDB before version 26.7.3, with no further details or evidence of exploitation, patches, or PoC.

    00000102
    4.1K followersView on X

Explore more