
ArcadeDB MCP had a settings tool that just returned the high-availability cluster token in cleartext (CVE-2026-67357). That token was enough to impersonate root through specific headers. Authenticated MCP client → cluster-level access. “Settings” endpoints that dump secrets are still one of the most reliable privilege pivots in new protocols. https://adversa.ai/blog/top-mcp-security-resources-september-2026/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec


