CVE-2026-48106
8.3Basekick-Labs · arc
The Basekick-Labs arc time-series database contains vulnerabilities involving missing authentication and insufficient data integrity verification for critical functions.
Executive summary
Basekick-Labs arc is affected by critical authentication and integrity flaws that allow authenticated users to perform unauthorized actions and manipulate database state.
Vulnerability
This issue encompasses multiple weaknesses, including CWE-306 (Missing Authentication for Critical Function) and CWE-924 (Improper Enforcement of Message Integrity), which allow a low-privileged authenticated attacker to bypass security controls and compromise data integrity.
Business impact
The ability to manipulate time-series data without proper authorization threatens the reliability of telemetry and monitoring systems. Given the CVSS score of 8.3, this high-severity vulnerability could lead to significant data corruption or the injection of false metrics, potentially resulting in incorrect operational decisions or service outages.
Remediation
Immediate Action: Upgrade to version 2026.06.1 or later to resolve the missing authentication and integrity verification flaws.
Proactive Monitoring: Review database access logs for unusual queries or modifications initiated by low-privileged service accounts.
Compensating Controls: Implement strict network segmentation and ensure that access to the database management interface is restricted to authorized administrative segments only.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing Basekick-Labs arc should prioritize upgrading to version 2026.06.1 immediately. Given the high impact on data integrity, failure to apply this update leaves telemetry environments susceptible to unauthorized manipulation and system compromise.