CVE-2026-86114

Summary

Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.

Affected Software

VendorProductVersion RangeStatus
getarcaneapparcane1.19.1 < 2.0.0affected

Weaknesses

  • CWE-862: Missing Authorization

References