SQL Injection Vulnerability in Arc Enterprise by Basekick Labs
CVE-2026-48105

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-48105?

Arc Enterprise, a SQL-native time-series database, has a vulnerability that allows attackers to exploit the manifest-registration process by submitting arbitrary file paths without adequate validation. Prior to version 26.06.1, the system only ensures that the path is non-empty, failing to implement necessary restrictions such as disallowing parent-traversal sequences, enforcing an allowlist of legitimate file path prefixes, or limiting the path length. As a result, this oversight opens up potential avenues for unauthorized file access. Users are encouraged to implement workarounds such as restricting network access to trusted peers and auditing the cluster manifest for any unexpected file paths. It is crucial to upgrade to the fixed version to mitigate risks associated with this vulnerability.

Affected Version(s)

arc < 2026.06.1

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.