ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-18 12:19
Updated : 2026-08-31 20:33
NVD link : CVE-2026-75852
Mitre link : CVE-2026-75852
CVE.ORG link : CVE-2026-75852
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
