PT-2026-86385 · Arcane · Arcane
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Arcane versions prior to 2.0.0
Description
Insufficient restrictions on template operations allow accounts with the default user role to create, modify, and delete compose templates, including instance-wide defaults. This allows for the injection of malicious container configurations featuring privileged settings or host path mounts, which execute with administrative privileges when deployed by administrators.
Recommendations
Update to version 2.0.0 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcane