CVE-2026-48106: CWE-306: Missing Authentication for Critical Function in Basekick-Labs arc
Description
CVE-2026-48106 is a high-severity vulnerability in Basekick-Labs' Arc, an open SQL-native time-series database. Versions prior to 26.06.1 have a missing authentication mechanism for the MsgReplicateSync payload in the cluster replication receiver, allowing application-layer message tampering or replay attacks despite transport-layer TLS/mTLS protection. The issue is fixed in version 26.06.1. Workarounds include restricting cluster network access, auditing replication logs, or disabling cluster mode until patched.
CVSS v4.0
Score 8.3high
Affected software
Basekick-Labs
arc
pkg:github/basekick-labs/arcRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Arc Enterprise's cluster replication receiver component validates only the wire-format envelope of inbound messages but does not authenticate the MsgReplicateSync payload at the application layer. This lack of HMAC, signature, or nonce protection allows an attacker with network access to the cluster to tamper with or replay replication messages. Although TLS/mTLS protects the transport layer, it does not prevent these application-layer attacks once a peer is on the cluster network. The vulnerability is addressed in Arc version 26.06.1.
Potential Impact
An attacker with access to the cluster network can tamper with or replay replication messages, potentially disrupting cluster replication integrity or causing unauthorized actions within the cluster. The vulnerability does not affect confidentiality but impacts integrity and availability of replication data.
Mitigation Recommendations
A fix is available in Arc version 26.06.1. Until the patch is applied, it is recommended to restrict cluster network access to trusted peers using strict firewall rules, audit replication logs for unexpected MsgReplicateSync traffic, and consider disabling cluster mode to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T18:46:58.285Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a88d6dfacd9273b49d6b7b2
Added to database: 08/21/2026, 22:53:19 UTC
Last enriched: 09/10/2026, 15:33:40 UTC
Last updated: 10/06/2026, 06:48:18 UTC
Views: 75
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.