CVE-2026-47735Patch

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-22)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-29: 1Mentions · 2026-08-22: 2Patch / Workaround · 2026-06-29: 1Technical Details · 2026-08-22: 106-2908-22
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-291
Patch1
2026-08-222
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-47735 Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked… https://www.cve.org/CVERecord?id=CVE-2026-47735 ----- Traducción: CVE-2026-47735 Arc… http://infoflow.cloud`

    Post summary

    The post simply references CVE-2026-47735 and notes a component path, but provides no details about exploitation, patches, or active attacks.

    0000036
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47735 Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked… https://www.cve.org/CVERecord?id=CVE-2026-47735

    Post summary

    The post announces a SQL injection vulnerability in Arc’s user‑SQL validator before version 26.06.1, citing the CVE record but offering no exploit code or patch details.

    00000840
    58.0K followersView on X
  • Ignacio Van Droogenbroeck@hectorivand
    Patch

    Arc 26.06.2 is out. For defense and regulated programs: FIPS 140-3 build (arc-fips), signed supply chain with SBOMs + cosign + SLSA Level 3 provenance, CVE-2026-47735 fully closed across the entire DuckDB table-function family. For everyone: single-hour flush 16ms → 1.25ms, 201MB allocated → 0B. Ingest ~20.0M → 20.9M rec/s. S3 batch-delete cuts compaction API calls by 1000×. Drop-in upgrade. https://basekick.net/blog/arc-release-26-06-2

    Post summary

    Arc 26.06.2 release fixes CVE-2026-47735, adds FIPS 140‑3 builds, supply‑chain signatures, and performance enhancements, providing a direct patch for the identified vulnerability.

    00000114
    1.4K followersView on X

Explore more