SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-48105

HIGH · CVSS 8.3 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Arc Enterprise versions prior to 26.06.1 are vulnerable due to insufficient validation of file paths in manifest-registration proposals, allowing attackers to potentially manipulate file storage locations. This could lead to unauthorized access or data corruption, posing a significant risk to the integrity of telemetry data. Organizations using Arc Enterprise should prioritize this vulnerability, especially those with exposed cluster networks or sensitive data, and implement recommended workarounds until the patch is applied.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48105
Severity
HIGH
CVSS
8.3
EPSS
0.17%

Original NVD Description

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in manifest-registration proposals without validating them against the configured storage backend. The only check is that the path is non-empty. There is no parent-traversal (`..`) rejection, no allowlist of legitimate prefixes, no scheme restriction (`s3://` vs local), and no length bound. This is fixed in 2026.06.1. Some workarounds are available. Restrict cluster network access to known-trusted peers via strict firewall rules, audit the cluster manifest for unexpected paths (any path not matching the configured storage backend root is suspect), and/or disable cluster mode until the fix is available.