Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Arc — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Arc, with AI-generated Chinese analysis, references, and POCs.

Vendor: CData

CVE ID Title CVSS Severity Published
CVE-2026-94181 Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element CWE-451 7.4 High 2026-09-23
CVE-2026-55678 Arc: Unauthenticated cluster node admission when `cluster.shared_secret` is unset CWE-284 6.9 Medium 2026-08-28
CVE-2026-48106 Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer CWE-306 8.3 High 2026-08-21
CVE-2026-48105 Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive CWE-22 8.3 High 2026-08-21
CVE-2026-47735 Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks CWE-22 7.1 High 2026-08-21
CVE-2026-48050 Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS CWE-200 8.8 High 2026-08-21
CVE-2026-33922 Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0 CWE-22 6.0 Medium 2026-08-11
CVE-2026-33921 Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0 CWE-1188 5.2 Medium 2026-08-11
CVE-2025-40896 Lack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.0 CWE-295 6.5 Medium 2026-03-04
CVE-2023-5938 Path traversal via 'zip slip' in Arc before v1.6.0 CWE-22 8.0 High 2024-05-15
CVE-2023-5937 Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0 CWE-538 3.8 Low 2024-05-15
CVE-2023-5936 Unsafe temporary data privileges on Unix systems in Arc before v1.6.0 CWE-732 7.8 High 2024-05-15
CVE-2023-5935 Missing authentication for local web interface in Arc before v1.6.0 CWE-306 7.4 High 2024-05-15
CVE-2024-31850 CData Arc 安全漏洞 CWE-22 8.6 High 2024-04-05

All 14 known CVE vulnerabilities affecting Arc with full Chinese analysis, references, and POCs where available.