CVE-2026-48106General

LOWCVSS 8.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope (length, opcode) of inbound messages. The `MsgReplicateSync` payload itself is accepted without any application-layer authentication — no HMAC, no signature, no per-message nonce. The replication stream is protected at the transport layer by TLS / mTLS, but there is no protection against application-layer message tampering or replay once a peer is on the cluster network. This is fixed in 2026.06.1. Some workarounds are available. Restrict cluster network access to known-trusted peers via strict firewall rules, audit replication logs for unexpected `MsgReplicateSync` traffic, and/or disable cluster mode until the fix is available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-345CWE-924

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-21: 208-21
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-48106 Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replicatio… https://www.cve.org/CVERecord?id=CVE-2026-48106 ----- Traducción: CVE-2026-48106 Arc… http://infoflow.cloud`

    Post summary

    The post merely announces CVE-2026-48106 for Arc with a link to the CVE record, offering no further technical, exploit, or mitigation details.

    0000020
    102 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-48106 Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replicatio… https://www.cve.org/CVERecord?id=CVE-2026-48106

    Post summary

    The text briefly mentions CVE-2026-48106 and references a version number, but provides minimal technical or operational details.

    00000973
    58.0K followersView on X

Explore more