PT-2026-86385 · Arcane · Arcane

·

CVE-2026-86114

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Arcane versions prior to 2.0.0
Description Insufficient restrictions on template operations allow accounts with the default user role to create, modify, and delete compose templates, including instance-wide defaults. This allows for the injection of malicious container configurations featuring privileged settings or host path mounts, which execute with administrative privileges when deployed by administrators.
Recommendations Update to version 2.0.0 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86114

Affected Products

Arcane