Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 10:16
Updated : 2026-09-14 20:17
NVD link : CVE-2026-86114
Mitre link : CVE-2026-86114
CVE.ORG link : CVE-2026-86114
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
