CVE-2026-75852

ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-18 12:19

Updated : 2026-08-31 20:33


NVD link : CVE-2026-75852

Mitre link : CVE-2026-75852

CVE.ORG link : CVE-2026-75852


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function