CVE-2026-86114
Arcane before 2.0.0 Missing Administrator Authorization on the Compose Template Mutation Endpoints
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
| CWE | CWE-862 |
| Vendor | getarcaneapp |
| Product | arcane |
| Published | Sep 5, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for getarcaneapp arcane
Be the first to know when new medium vulnerabilities affecting getarcaneapp arcane are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
getarcaneapp / arcane
1.19.1 < 2.0.0
References
github.com: https://github.com/geo-chen/oss/blob/main/arcane.md github.com: https://github.com/getarcaneapp/arcane/blob/v1.19.5/backend/api/handlers/templates.go github.com: https://github.com/getarcaneapp/arcane/commit/1500646aa91f github.com: https://github.com/getarcaneapp/arcane/releases/tag/v2.0.0 github.com: https://github.com/getarcaneapp/arcane vulncheck.com: https://www.vulncheck.com/advisories/arcane-before-2.0.0-missing-administrator-authorization-on-the-compose-template-mutation-endpoints
Credits
๐ George Chen