PT-2026-79498 · Unknown · Arc Enterprise

CVE-2026-48105

·

Published

2026-08-21

·

Updated

2026-08-22

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Arc Enterprise versions prior to 26.06.1
Description Arc Enterprise's Raft FSM (Finite State Machine) in the applyRegisterFile() function accepts attacker-chosen file paths in manifest-registration proposals without validating them against the configured storage backend. The system only verifies that the path is not empty, failing to reject parent-traversal (..) sequences, enforce an allowlist of legitimate prefixes, restrict schemes (such as s3:// versus local), or apply length bounds. This allows for a cluster-wide path-traversal worm primitive.
Recommendations Update to version 26.06.1. Restrict cluster network access to known-trusted peers using strict firewall rules. Audit the cluster manifest for unexpected paths that do not match the configured storage backend root. Disable cluster mode until the fix is applied.

Fix

Path traversal

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48105

Affected Products

Arc Enterprise