ZeroHour

CVE-2026-86114

niche

Missing Authorization in Arcane Lets Low-Privileged Users Tamper With Compose Templates

CVSS 4.0
7.1 high
EPSS
<1%p15
Published
()
Modified
AI analysis

Arcane before 2.0.0 does not properly enforce authorization (CWE-862) on compose template operations, so accounts holding only the default user role can create, modify, and delete templates, including instance-wide defaults. An attacker with such an account can inject a malicious container configuration using privileged settings or host path mounts into a shared template. When an administrator later deploys that template, the injected container runs with administrative-level privileges, giving the attacker effectively privileged code execution in the deployment. Any Arcane deployment running a version prior to 2.0.0 that grants access to default user role accounts is affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.

What to do: Upgrade Arcane to version 2.0.0 or later, which restores proper authorization on template operations. Until upgraded, restrict or review which accounts hold the default user role and audit existing compose templates (especially instance-wide defaults) for unexplained privileged settings or host path mounts that a low-privileged user may have injected.

Affected
Arcane (open-source project) Arcaneall versions before 2.0.0
Estimated exposure
nichelikely low thousands of self-hosted deployments (exact counts unknown) — Arcane is a niche self-hosted Docker management UI with no public install-count data, so deployments are estimated in the low thousands based on typical adoption of newer open-source Portainer-style tools; also unknown how many of those…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.