Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators. | |
| Title | Arcane before 2.0.0 Missing Administrator Authorization on the Compose Template Mutation Endpoints | |
| First Time appeared |
Getarcane
Getarcane arcane |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:getarcane:arcane:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getarcane
Getarcane arcane |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T09:59:05.356Z
Reserved: 2026-09-05T01:59:20.258Z
Link: CVE-2026-86114
No data.
Status : Received
Published: 2026-09-05T10:16:42.423
Modified: 2026-09-05T10:16:42.423
Link: CVE-2026-86114
No data.
OpenCVE Enrichment
Updated: 2026-09-05T12:00:05Z
Weaknesses