CVE-2026-48050: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in Basekick-Labs arc
Description
CVE-2026-48050 is a high-severity vulnerability in Basekick-Labs' Arc time-series database prior to version 26.06.1. The issue arises because the application registers Go's pprof debugging endpoints under /debug/pprof/* without proper authentication, allowing unauthorized access to sensitive profiling information. This exposure occurs due to the authentication middleware bypassing token checks for these endpoints. The vulnerability is patched in version 26.06.1. Workarounds include blocking access to /debug/pprof* at the reverse proxy or load balancer, restricting API port access via firewall rules, or disabling the pprof handler in the source code and rebuilding the application.
CVSS v4.0
Score 8.8high
Affected software
Basekick-Labs
arc
pkg:github/basekick-labs/arcRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Arc, an open SQL-native time-series database, versions prior to 26.06.1 expose sensitive profiling information via Go's net/http/pprof endpoints at /debug/pprof/* without authentication. This happens because the authentication middleware short-circuits before token validation on matching public prefixes, including /debug/pprof. The vulnerability is identified as CWE-200 (Exposure of Sensitive Information) and related weaknesses CWE-306 and CWE-400. Version 26.06.1 includes a patch that removes this exposure. Mitigations include blocking the /debug/pprof endpoints at the network edge, restricting access to trusted networks, or disabling the pprof handler in the source code.
Potential Impact
Unauthorized actors can access sensitive profiling data through the exposed /debug/pprof endpoints without authentication. This information disclosure can aid attackers in understanding the internal state and performance characteristics of the database, potentially facilitating further attacks or reconnaissance. The vulnerability has a CVSS 4.0 score of 8.8 (high severity), indicating significant risk if exploited.
Mitigation Recommendations
A patch is available in Arc version 26.06.1 that addresses this vulnerability. Users should upgrade to this version to remediate the issue. If immediate patching is not possible, workarounds include blocking access to /debug/pprof* endpoints at the reverse proxy or load balancer, restricting Arc's API port to trusted networks via firewall rules, or disabling the pprof handler by commenting out app.Use(pprof.New()) in internal/api/server.go and rebuilding the application.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T18:15:53.578Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a88d6dfacd9273b49d6b7ae
Added to database: 08/21/2026, 22:53:19 UTC
Last enriched: 09/10/2026, 15:33:51 UTC
Last updated: 10/06/2026, 18:48:22 UTC
Views: 86
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.