CyberRota Analysis
AI-GeneratedArc Enterprise versions prior to 26.06.1 are vulnerable due to insufficient validation of file paths in manifest-registration proposals, allowing attackers to potentially manipulate file storage locations. This could lead to unauthorized access or data corruption, posing a significant risk to the integrity of telemetry data. Organizations using Arc Enterprise should prioritize this vulnerability, especially those with exposed cluster networks or sensitive data, and implement recommended workarounds until the patch is applied.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in manifest-registration proposals without validating them against the configured storage backend. The only check is that the path is non-empty. There is no parent-traversal (`..`) rejection, no allowlist of legitimate prefixes, no scheme restriction (`s3://` vs local), and no length bound. This is fixed in 2026.06.1. Some workarounds are available. Restrict cluster network access to known-trusted peers via strict firewall rules, audit the cluster manifest for unexpected paths (any path not matching the configured storage backend root is suspect), and/or disable cluster mode until the fix is available.