SQL Injection Vulnerability in Arc Enterprise by Basekick Labs
CVE-2026-48105
What is CVE-2026-48105?
Arc Enterprise, a SQL-native time-series database, has a vulnerability that allows attackers to exploit the manifest-registration process by submitting arbitrary file paths without adequate validation. Prior to version 26.06.1, the system only ensures that the path is non-empty, failing to implement necessary restrictions such as disallowing parent-traversal sequences, enforcing an allowlist of legitimate file path prefixes, or limiting the path length. As a result, this oversight opens up potential avenues for unauthorized file access. Users are encouraged to implement workarounds such as restricting network access to trusted peers and auditing the cluster manifest for any unexpected file paths. It is crucial to upgrade to the fixed version to mitigate risks associated with this vulnerability.
Affected Version(s)
arc < 2026.06.1
