Arc
This hub aggregates every CVE we track for Arc, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
25
CVEs tracked
2
Critical
9
High
0
In CISA KEV
Severity distribution
HIGH9MEDIUM6LOW3CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
1
0
0
0
0
7
2
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Arc.
- CVE-2026-94181Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element7.4
- CVE-2026-33389Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.07.5
- CVE-2026-55678Arc: Unauthenticated cluster node admission when `cluster.shared_secret` is unset
- CVE-2026-48106Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer
- CVE-2026-48105Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive
- CVE-2026-47735Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks
- CVE-2026-48050Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS
- CVE-2026-33922Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.06.0
- CVE-2026-33921Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.05.2
- CVE-2025-40896Lack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.06.5
- CVE-2024-52928Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.9.6
- CVE-2024-45489Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to ...9.8
- CVE-2023-5938Path traversal via 'zip slip' in Arc before v1.6.08.0
- CVE-2023-5937Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.03.8
- CVE-2023-5936Unsafe temporary data privileges on Unix systems in Arc before v1.6.07.8
Product normalization is registry-driven with AI assist and human review. How it works