Description
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
Published: 2026-09-05
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

Arcane versions before 2.0.0 allow accounts with a default user role to create, modify, and delete compose templates, including instance-wide defaults. Because these templates can contain malicious container configurations with privileged settings or host path mounts, an attacker who can influence template content can cause containers to run with administrative privileges when an administrator deploys them. This flaw arises from missing authorization checks on the Compose Template Mutation endpoints (CWE-862) and can lead to privilege escalation and potentially remote code execution within containers that are run by administrators.

Affected Systems

The affected product is Arcane, version 1.x up to but not including 2.0.0. The CNA vendor identified is getarcaneapp (Arcane). All deployments of Arcane older than 2.0.0 are potentially vulnerable; the specific versions referenced include v1.19.5 and earlier releases. No further version granularity is provided beyond the 2.0.0 release marker.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score is not available, so the risk of exploitation cannot be quantified precisely, but the lack of authentication controls indicates a high likelihood that an attacker could discover or craft a malicious template. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported, yet it remains exploitable. The likely attack vector is an attacker with access to the Arcane API as a default user role, who can post a malicious compose template that administrators later deploy with elevated privileges.

Generated by OpenCVE AI on September 5, 2026 at 11:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Arcane to version 2.0.0 or newer to restore proper authorization checks on template mutation endpoints.
  • Revoke default user role permissions for composing, editing, or deleting templates and enforce strict role‑based access control so that only administrators can perform these actions.
  • Audit existing compose templates for privileged container configurations or host path mounts and remove or remediate any that pose a risk.
  • Review and monitor Arcane logs for unauthorized template creation or modifications after patch installation.

Generated by OpenCVE AI on September 5, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 05 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
Title Arcane before 2.0.0 Missing Administrator Authorization on the Compose Template Mutation Endpoints
First Time appeared Getarcane
Getarcane arcane
Weaknesses CWE-862
CPEs cpe:2.3:a:getarcane:arcane:*:*:*:*:*:*:*:*
Vendors & Products Getarcane
Getarcane arcane
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Getarcane Arcane
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:01.502Z

Reserved: 2026-09-05T01:59:20.258Z

Link: CVE-2026-86114

cve-icon Vulnrichment

Updated: 2026-09-14T19:23:41.959Z

cve-icon NVD

Status : Deferred

Published: 2026-09-05T10:16:42.423

Modified: 2026-09-23T17:17:46.890

Link: CVE-2026-86114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T12:00:05Z

Weaknesses