SQL-Native Time-Series Database Vulnerability in Arc by Basekick Labs
CVE-2026-48050
8.8HIGH
What is CVE-2026-48050?
Arc is an open, SQL-native time-series database for telemetry, which in versions before 26.06.1, improperly manages authentication for its /debug/pprof/* handlers. The issue arises from the auth middleware not being effectively engaged, allowing unauthorized access to sensitive debugging endpoints without authentication. The patch for this vulnerability is available in version 26.06.1. Users are advised to consider alternative workarounds, such as blocking the relevant endpoints at a reverse proxy or adjusting firewall rules to limit access to recognized networks, as well as rebuilding the software after removing the potentially vulnerable code segment.
Affected Version(s)
arc < 26.06.1
