Arcane
Getarcaneapp · 10 CVEs
Arcane before 2.0.0 Missing Administrator Authorization on the Compose Template Mutation Endpoints
Sep 5, 2026
Arcane: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credent…
May 29, 2026
Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter
May 29, 2026
Arcane: Unauthenticated reflected XSS via SVG color parameter in /api/app-images/logo enables admin account takeover
May 29, 2026
Arcane: Missing admin authorization on global variables endpoint
May 29, 2026
Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcane
May 29, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets)
May 9, 2026
Arcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
Apr 10, 2026
Arcane allows unauthenticated proxy access to remote environments
Jan 19, 2026
Arcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE
Jan 15, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-86114 | Arcane before 2.0.0 Missing Administrator Authorization on the Compose Template Mutation Endpoints | HIGH | 0.43% | Sep 5, 2026 |
| CVE-2026-45625 | Arcane: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs | CRITICAL | 0.52% | May 29, 2026 |
| CVE-2026-45626 | Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter | MEDIUM | 0.36% | May 29, 2026 |
| CVE-2026-45627 | Arcane: Unauthenticated reflected XSS via SVG color parameter in /api/app-images/logo enables admin account takeover | HIGH | 0.32% | May 29, 2026 |
| CVE-2026-47125 | Arcane: Missing admin authorization on global variables endpoint | HIGH | 0.42% | May 29, 2026 |
| CVE-2026-47179 | Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcane | HIGH | 0.46% | May 29, 2026 |
| CVE-2026-42461 | Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) | HIGH | 1.47% | May 9, 2026 |
| CVE-2026-40242 | Arcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint | HIGH | 0.72% | Apr 10, 2026 |
| CVE-2026-23944 | Arcane allows unauthenticated proxy access to remote environments | HIGH | 0.52% | Jan 19, 2026 |
| CVE-2026-23520 | Arcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE | CRITICAL | 1.87% | Jan 15, 2026 |
Showing 1 to 10 of 10 CVEs