Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-48106: CWE-306: Missing Authentication for Critical Function in Basekick-Labs arc

0
High
VulnerabilityCVE-2026-48106cvecve-2026-48106cwe-306cwe-345cwe-924
Published: 08/21/2026 (08/21/2026, 22:49:12 UTC)
Source: CVE Database V5
Vendor/Project: Basekick-Labs
Product: arc

Description

Arc, an open SQL-native time-series database by Basekick-Labs, has a vulnerability in versions prior to 26.06.1 where the cluster replication receiver does not authenticate the MsgReplicateSync payload at the application layer. While TLS/mTLS protects the transport layer, there is no protection against message tampering or replay attacks once inside the cluster network. This issue is fixed in version 26.06.1. Workarounds include restricting cluster network access, auditing replication logs, or disabling cluster mode until patched.

CVSS v4.0

Score 8.3high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
High
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N

Affected software

GitHub Actionsmore threats →ai
basekick-labs/arc
pkg:github/basekick-labs/arc
Affected versions
<26.06.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/21/2026, 23:07:17 UTC

Technical Analysis

CVE-2026-48106 affects Basekick-Labs' Arc database prior to version 26.06.1. The cluster replication receiver component validates only the wire-format envelope of inbound replication messages but does not perform application-layer authentication on the MsgReplicateSync payload. This lack of HMAC, signature, or nonce protection allows potential message tampering or replay attacks within the cluster network despite TLS/mTLS securing transport. The vulnerability is addressed in version 26.06.1. Until patched, mitigating controls such as network access restrictions and log auditing are recommended.

Potential Impact

An attacker with access to the cluster network can tamper with or replay replication messages, potentially disrupting cluster replication integrity. The vulnerability does not allow bypass of transport-layer encryption but exposes the application layer to manipulation, which could lead to data inconsistency or denial of service within the cluster replication process.

Mitigation Recommendations

A fix is available in Arc version 26.06.1. Until upgrading, it is recommended to restrict cluster network access to trusted peers using strict firewall rules, audit replication logs for unexpected MsgReplicateSync traffic, and consider disabling cluster mode to prevent exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-05-20T18:46:58.285Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a88d6dfacd9273b49d6b7b2

Added to database: 08/21/2026, 22:53:19 UTC

Last enriched: 08/21/2026, 23:07:17 UTC

Last updated: 08/22/2026, 02:56:39 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses