CVE-2026-86114

Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 10:16

Updated : 2026-09-14 20:17


NVD link : CVE-2026-86114

Mitre link : CVE-2026-86114

CVE.ORG link : CVE-2026-86114


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization