Critical severity9.8NVD Advisory· Published Aug 18, 2026
CVE-2026-75852
CVE-2026-75852
Description
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <26.8.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.