Authentication Bypass in Arc Enterprise Clustering by Basekick Labs
CVE-2026-55678

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55678?

Arc Enterprise clustering suffers from an authentication bypass vulnerability that allows unauthenticated attackers to exploit clustering functionalities. When clustering is enabled without a configured shared secret, attackers can send join requests and assume the identity of a trusted cluster node. This facilitates unauthorized manipulation of cluster membership, unauthorized access to sensitive operational data, and the ability to intercept and forward requests. Deployments that utilize clustering with the default configuration and no shared secret are particularly vulnerable. Upgrading to version 26.06.2 mitigates this issue.

Affected Version(s)

arc >= 26.02.1, < 26.06.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.