CVE-2026-75852

CRITICAL CVSS 4.0: 9.3 EPSS 0.45%
Updated Aug 18, 2026
MongoDB
Parameter Value
CVSS 9.3 (CRITICAL)
Affected Versions before 26.8.1
Type CWE-306 (Missing Authentication for Critical Function)
Vendor MongoDB
Public PoC No

ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0