GHSA-pj2x-fr4j-wrxqHighCVSS 6.5
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user...
🔗 CVE IDs covered (1)
📋 Description
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-86114
- https://github.com/getarcaneapp/arcane/commit/1500646aa91f
- https://github.com/geo-chen/oss/blob/main/arcane.md
- https://github.com/getarcaneapp/arcane
- https://github.com/getarcaneapp/arcane/blob/v1.19.5/backend/api/handlers/templates.go
- https://github.com/getarcaneapp/arcane/releases/tag/v2.0.0
- https://www.vulncheck.com/advisories/arcane-before-2.0.0-missing-administrator-authorization-on-the-compose-template-mutation-endpoints
- https://github.com/advisories/GHSA-pj2x-fr4j-wrxq