SQL-Native Time-Series Database Vulnerability in Arc by Basekick Labs
CVE-2026-48050

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-48050?

Arc is an open, SQL-native time-series database for telemetry, which in versions before 26.06.1, improperly manages authentication for its /debug/pprof/* handlers. The issue arises from the auth middleware not being effectively engaged, allowing unauthorized access to sensitive debugging endpoints without authentication. The patch for this vulnerability is available in version 26.06.1. Users are advised to consider alternative workarounds, such as blocking the relevant endpoints at a reverse proxy or adjusting firewall rules to limit access to recognized networks, as well as rebuilding the software after removing the potentially vulnerable code segment.

Affected Version(s)

arc < 26.06.1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.