CVE-2026-86114

Source
https://cve.org/CVERecord?id=CVE-2026-86114
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86114.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86114
Published
2026-09-05T09:59:05Z
Modified
2026-09-07T03:45:35Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Arcane before 2.0.0 Missing Administrator Authorization on the Compose Template Mutation Endpoints
Details

Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86114.json"
}
References

Affected packages

Git / github.com/getarcaneapp/arcane

Affected ranges

Type
GIT
Repo
https://github.com/getarcaneapp/arcane
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.19.1"
        },
        {
            "fixed": "2.0.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

backend/v1.*
backend/v1.19.1
backend/v1.19.2
backend/v1.19.3
backend/v1.19.4
backend/v1.19.5
backend/v1.20.0
cli/v1.*
cli/v1.19.1
cli/v1.19.2
cli/v1.19.3
cli/v1.19.4
cli/v1.19.5
cli/v1.20.0
types/v1.*
types/v1.19.1
types/v1.19.2
types/v1.19.3
types/v1.19.4
types/v1.19.5
types/v1.20.0
v1.*
v1.19.1
v1.19.2
v1.19.3
v1.19.4
v1.19.5
v1.20.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86114.json"