Application Layer Vulnerability in Arc Enterprise Database by Basekick Labs
CVE-2026-48106

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-48106?

Arc Enterprise, an open SQL-native time-series database, contains a vulnerability in its cluster replication mechanism. Prior to version 26.06.1, the database fails to authenticate the payload of the MsgReplicateSync message, which leaves it open to application-layer message tampering and replay attacks. While the replication stream is protected by TLS/mTLS at the transport layer, this vulnerability allows unauthorized message manipulation once a peer joins the cluster network. To mitigate risks, administrators are advised to enforce strict firewall rules for network access, regularly review replication logs for anomalies, and consider disabling cluster mode until the update is applied.

Affected Version(s)

arc < 2026.06.1

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.