Authentication Bypass in Arc Enterprise Clustering by Basekick Labs
CVE-2026-55678
6.9MEDIUM
What is CVE-2026-55678?
Arc Enterprise clustering suffers from an authentication bypass vulnerability that allows unauthenticated attackers to exploit clustering functionalities. When clustering is enabled without a configured shared secret, attackers can send join requests and assume the identity of a trusted cluster node. This facilitates unauthorized manipulation of cluster membership, unauthorized access to sensitive operational data, and the ability to intercept and forward requests. Deployments that utilize clustering with the default configuration and no shared secret are particularly vulnerable. Upgrading to version 26.06.2 mitigates this issue.
Affected Version(s)
arc >= 26.02.1, < 26.06.2
