CVE-2026-86114
nicheMissing Authorization in Arcane Lets Low-Privileged Users Tamper With Compose Templates
Arcane before 2.0.0 does not properly enforce authorization (CWE-862) on compose template operations, so accounts holding only the default user role can create, modify, and delete templates, including instance-wide defaults. An attacker with such an account can inject a malicious container configuration using privileged settings or host path mounts into a shared template. When an administrator later deploys that template, the injected container runs with administrative-level privileges, giving the attacker effectively privileged code execution in the deployment. Any Arcane deployment running a version prior to 2.0.0 that grants access to default user role accounts is affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.
What to do: Upgrade Arcane to version 2.0.0 or later, which restores proper authorization on template operations. Until upgraded, restrict or review which accounts hold the default user role and audit existing compose templates (especially instance-wide defaults) for unexplained privileged settings or host path mounts that a low-privileged user may have injected.
| Arcane (open-source project) Arcane | all versions before 2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.