๐Ÿ” CVE Alert

CVE-2026-47125

HIGH 8.8

Arcane: Missing admin authorization on global variables endpoint

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
12th

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitution in every project's compose file, is missing an admin authorization check. Any authenticated non-admin user can call this endpoint with their bearer token or API key and overwrite the global environment variables that are merged into every project deployment. By overriding values like REGISTRY, IMAGE, DATABASE_URL, or SECRET_KEY that other users reference via ${VAR} in compose files, an attacker can redirect image pulls to attacker-controlled registries (supply-chain RCE on the Docker host), exfiltrate database credentials, or disrupt all projects. This vulnerability is fixed in 1.19.2.

CWE CWE-862
Vendor getarcaneapp
Product arcane
Published May 29, 2026
Last Updated Jun 1, 2026
Stay Ahead of the Next One

Get instant alerts for getarcaneapp arcane

Be the first to know when new high vulnerabilities affecting getarcaneapp arcane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

getarcaneapp / arcane
< 1.19.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/getarcaneapp/arcane/security/advisories/GHSA-jpjh-jm2p-39hh