CVE-2026-42461
Description
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/templates* in Arcane's Huma backend are registered without any Security requirement, allowing any unauthenticated network client to list and read the full Compose YAML and .env content of every custom template stored in the instance. Because Arcane's UI exposes a "Save as Template" flow on the project / swarm-stack creation pages that persists the operator's real env content (database passwords, API keys, etc.) verbatim, this missing authorization is an unauthenticated read of operator secrets in practice — not a theoretical info-disclosure. The frontend explicitly treats /customize/templates/* as an authenticated area (PROTECTED_PREFIXES in frontend/src/lib/utils/redirect.util.ts), and every CRUD operation (POST/PUT/DELETE) on the same paths requires a Bearer/API key, so this is a clear backend authorization gap, not intended public access. This issue has been patched in version 1.18.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/getarcaneapp/arcane/backendGo | < 1.18.0 | 1.18.0 |
Affected products
1- Range: < 1.18.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-cxx3-hr75-4q96ghsaADVISORY
- github.com/getarcaneapp/arcane/security/advisories/GHSA-cxx3-hr75-4q96nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-42461ghsaADVISORY
- github.com/getarcaneapp/arcane/releases/tag/v1.18.0nvdProductRelease NotesWEB
News mentions
0No linked articles in our index yet.