CVE-2026-48105Disclosure

LOWCVSS 8.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in manifest-registration proposals without validating them against the configured storage backend. The only check is that the path is non-empty. There is no parent-traversal (`..`) rejection, no allowlist of legitimate prefixes, no scheme restriction (`s3://` vs local), and no length bound. This is fixed in 2026.06.1. Some workarounds are available. Restrict cluster network access to known-trusted peers via strict firewall rules, audit the cluster manifest for unexpected paths (any path not matching the configured storage backend root is suspect), and/or disable cluster mode until the fix is available.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-345CWE-913

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-21: 2Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 208-21
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-48105 Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) … https://www.cve.org/CVERecord?id=CVE-2026-48105 ----- Traducción: CVE-2026-48105 Arc… http://infoflow.cloud`

    Post summary

    CVE-2026-48105 is disclosed, affecting Arc Enterprise’s Raft FSM before version 26.06.1, with a reference to the official CVE record.

    0000072
    102 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-48105 Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) … https://www.cve.org/CVERecord?id=CVE-2026-48105

    Post summary

    The text reports a CVE in Arc impacting versions before 26.06.1, references the affected code, and implies the issue is fixed in the newer release, but offers no exploits or active usage evidence.

    000001.1K
    58.0K followersView on X

Explore more