PT-2026-79498 · Unknown · Arc Enterprise
CVE-2026-48105
·
Published
2026-08-21
·
Updated
2026-08-22
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Arc Enterprise versions prior to 26.06.1
Description
Arc Enterprise's Raft FSM (Finite State Machine) in the
applyRegisterFile() function accepts attacker-chosen file paths in manifest-registration proposals without validating them against the configured storage backend. The system only verifies that the path is not empty, failing to reject parent-traversal (..) sequences, enforce an allowlist of legitimate prefixes, restrict schemes (such as s3:// versus local), or apply length bounds. This allows for a cluster-wide path-traversal worm primitive.Recommendations
Update to version 26.06.1.
Restrict cluster network access to known-trusted peers using strict firewall rules.
Audit the cluster manifest for unexpected paths that do not match the configured storage backend root.
Disable cluster mode until the fix is applied.
Fix
Path traversal
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Arc Enterprise