CVE-2026-48105
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Summary
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (internal/cluster/raft/fsm.go:applyRegisterFile) accepts attacker-chosen file paths in manifest-registration proposals without validating them against the configured storage backend. The only check is that the path is non-empty. There is no parent-traversal (..) rejection, no allowlist of legitimate prefixes, no scheme restriction (s3:// vs local), and no length bound. This is fixed in 2026.06.1. Some workarounds are available. Restrict cluster network access to known-trusted peers via strict firewall rules, audit the cluster manifest for unexpected paths (any path not matching the configured storage backend root is suspect), and/or disable cluster mode until the fix is available.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Basekick-Labs | arc | < 2026.06.1 | affected |
Weaknesses
- CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-345: CWE-345: Insufficient Verification of Data Authenticity
- CWE-913: CWE-913: Improper Control of Dynamically-Managed Code Resources
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.