CVE-2026-86114
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
- Published Sep 5, 2026
- CVSS 7.1 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available