๐Ÿ” CVE Alert

CVE-2026-55678

UNKNOWN 0.0

Arc: Unauthenticated cluster node admission when `cluster.shared_secret` is unset

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but cluster.shared_secret is not configured. The defaults in internal/config/config.go set cluster.enabled to false, cluster.cluster_name to arc-cluster, cluster.coordinator_addr to :9100, cluster.shared_secret to an empty value, and cluster.tls_enabled to false, while cmd/arc/main.go requires cluster.shared_secret only when cluster.replication_enabled is true. JoinRequest in internal/cluster/protocol/messages.go accepts attacker-controlled node_id, role, raft_addr, api_addr, and coord_addr values, plus optional auth_nonce, auth_timestamp, and auth_hmac fields. The join path in internal/cluster/coordinator.go validates HMAC authentication only when the configured shared secret is non-empty and otherwise proceeds after only the cluster-name check. An accepted node is marked healthy, added as a Raft voter or registered locally, and becomes available through internal/cluster/registry.go to the routing logic in internal/cluster/router.go. The forwardRequest path in internal/cluster/router.go builds its target from node.APIAddress and copies Authorization and x-api-key headers with the request, so a rogue node selected for a forwarded query or write can receive authentication headers, request bodies, database and measurement names, and operational metadata. Heartbeat in internal/cluster/protocol/messages.go also lacks HMAC fields, and internal/cluster/coordinator.go updates node state from supplied node_id and state values without authentication. An unauthenticated network attacker who can reach the coordinator port and knows the cluster name can therefore become a trusted cluster node, mutate cluster membership, be submitted as a Raft voter, intercept topology-dependent forwarded requests, divert or forge operations, and blackhole or delay traffic. The default standalone configuration is not reachable because cluster.enabled is false, but Enterprise cluster deployments with clustering enabled and no shared secret are affected. This issue is fixed in version 26.06.2.

CWE CWE-284 CWE-287 CWE-306
Vendor basekick-labs
Product arc
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for basekick-labs arc

Be the first to know when new unknown vulnerabilities affecting basekick-labs arc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Basekick-Labs / arc
>= 26.02.1, < 26.06.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Basekick-Labs/arc/security/advisories/GHSA-p378-jp5r-gpgw github.com: https://github.com/Basekick-Labs/arc/pull/505 github.com: https://github.com/Basekick-Labs/arc/commit/38402ad2ebddd32c15bf4a0fc9c22c920e5685df github.com: https://github.com/Basekick-Labs/arc/releases/tag/v26.06.2