Medium severity6.5NVD Advisory· Published Sep 5, 2026
CVE-2026-86114
CVE-2026-86114
Description
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
Affected products
1- Range: <2.0.0
Patches
Vulnerability mechanics
References
5- github.com/geo-chen/oss/blob/main/arcane.mdnvd
- github.com/getarcaneapp/arcane/blob/v1.19.5/backend/api/handlers/templates.gonvd
- github.com/getarcaneapp/arcane/commit/1500646aa91fnvd
- github.com/getarcaneapp/arcane/releases/tag/v2.0.0nvd
- www.vulncheck.com/advisories/arcane-before-2.0.0-missing-administrator-authorization-on-the-compose-template-mutation-endpointsnvd
News mentions
0No linked articles in our index yet.