Impact
Arcane versions before 2.0.0 allow accounts with a default user role to create, modify, and delete compose templates, including instance-wide defaults. Because these templates can contain malicious container configurations with privileged settings or host path mounts, an attacker who can influence template content can cause containers to run with administrative privileges when an administrator deploys them. This flaw arises from missing authorization checks on the Compose Template Mutation endpoints (CWE-862) and can lead to privilege escalation and potentially remote code execution within containers that are run by administrators.
Affected Systems
The affected product is Arcane, version 1.x up to but not including 2.0.0. The CNA vendor identified is getarcaneapp (Arcane). All deployments of Arcane older than 2.0.0 are potentially vulnerable; the specific versions referenced include v1.19.5 and earlier releases. No further version granularity is provided beyond the 2.0.0 release marker.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score is not available, so the risk of exploitation cannot be quantified precisely, but the lack of authentication controls indicates a high likelihood that an attacker could discover or craft a malicious template. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported, yet it remains exploitable. The likely attack vector is an attacker with access to the Arcane API as a default user role, who can post a malicious compose template that administrators later deploy with elevated privileges.
OpenCVE Enrichment