CRITICALVulnerability
CVE-2026-75852
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
Properties
- severity
- CRITICAL
- score
- 9.8
- epss_score
- 0.00451
- cve_id
- CVE-2026-75852
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-08-18T12:19:35.593
- last_modified
- 2026-08-31T20:33:07.713
- epss_percentile
- 0.37663
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Missing Authentication for Critical Function
Explore deeper with Ninja Signal's threat intelligence graph