๐Ÿ” CVE Alert

CVE-2026-48106

UNKNOWN 0.0

Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope (length, opcode) of inbound messages. The `MsgReplicateSync` payload itself is accepted without any application-layer authentication โ€” no HMAC, no signature, no per-message nonce. The replication stream is protected at the transport layer by TLS / mTLS, but there is no protection against application-layer message tampering or replay once a peer is on the cluster network. This is fixed in 2026.06.1. Some workarounds are available. Restrict cluster network access to known-trusted peers via strict firewall rules, audit replication logs for unexpected `MsgReplicateSync` traffic, and/or disable cluster mode until the fix is available.

CWE CWE-306 CWE-345 CWE-924
Vendor basekick-labs
Product arc
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for basekick-labs arc

Be the first to know when new unknown vulnerabilities affecting basekick-labs arc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Basekick-Labs / arc
< 2026.06.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Basekick-Labs/arc/security/advisories/GHSA-wfgr-8x84-22q7