arcane vulnerability

Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.

Published 5 Sep 2026Updated 5 Sep 20266 sources
CVSS 7.1

Source timeline

CVE record published by NVDView source ↗