CVE-2026-48106 | Basekick-Labs Arc up to 2026.06.0 Cluster Replication Receiver receiver.go authentication replay
A vulnerability classified as critical has been found in Basekick-Labs Arc up to 2026.06.0. Impacted is an unknown function of the file internal/cluster/replication/receiver.go of the component Cluster Replication Receiver. This manipulation causes authentication bypass by capture-replay.
This vulnerability is tracked as CVE-2026-48106. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More