CVE-2026-48050
Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `PublicPrefixes` in `cmd/arc/main.go`. The auth middleware short-circuits before the token check on prefix match, so the endpoints are reachable without any authentication. Version 26.06.1 contains a patch. Some workarounds are available. Block `/debug/pprof*` at a reverse proxy / load balancer in front of Arc, restrict Arc's API port to known-trusted networks via firewall rules, and/or patch the running build: comment out `app.Use(pprof.New())` in `internal/api/server.go` and rebuild.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.36%
- CWE
- CWE-200, CWE-306, CWE-400
- Published
- 2026-08-21
- Last modified
- 2026-08-25
Affected products
- Basekick-Labs arc
Weakness type
Related vulnerabilities
- CVE-2026-92960 — vm2 before 3.11.6 Process-wide State Exposure via os and dns
- CVE-2026-92947 — vm2 before 3.11.7 Memory Disclosure via Buffer Pool
- CVE-2026-87820 — CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity
- CVE-2026-67100 — HCL BigFix Service Management is affected by multiple security vulnerabilities.
- CVE-2026-54617 — GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler
- CVE-2026-87541 — Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the
- CVE-2026-78960 — Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin