PT-2026-79499 · Unknown · Arc Enterprise
CVE-2026-48106
·
Published
2026-08-21
·
Updated
2026-08-22
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Arc Enterprise versions prior to 26.06.1
Description
The cluster replication receiver at
internal/cluster/replication/receiver.go validates only the wire-format envelope of inbound messages. The MsgReplicateSync payload is accepted without application-layer authentication, such as HMAC, signatures, or per-message nonces. While the replication stream uses TLS/mTLS for transport layer protection, there is no defense against application-layer message tampering or replay attacks if a peer has access to the cluster network, potentially allowing cluster-wide data injection.Recommendations
Update to version 26.06.1.
Restrict cluster network access to known-trusted peers using strict firewall rules.
Audit replication logs for unexpected
MsgReplicateSync traffic.
Disable cluster mode as a temporary measure.Fix
Missing Authentication
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Arc Enterprise