Threat · curated 19 Aug 2026
CVE Record: CVE-2026-75845
First reported · updated · 2 reports cve.org
Coverage timeline
Why it matters
CVE-2026-75845 shows how an MCP server tool exposed by ArcadeDB can be abused by a low-privileged authenticated user to tamper with server configuration or cause denial of service, underscoring the need to enforce per-caller authorization on agent-facing tools.
CVE-2026-75845 is an authorization bypass in ArcadeDB's set_server_setting MCP server-level tool (versions 26.4.2 through 26.7.3). SetServerSettingTool.execute() checks only the global allowAdmin flag and never validates the caller's role, so in an MCP deployment with allowAdmin=true and a non-root allowedUsers set, any authenticated read-only user can invoke the tool to modify server GlobalConfiguration, enabling configuration tampering or denial of service. The issue is fixed in 26.8.1.