{"id":"CVE-2026-86114","summary":"Arcane before 2.0.0 Missing Administrator Authorization on the Compose Template Mutation Endpoints","details":"Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.","modified":"2026-09-07T03:45:35.951451724Z","published":"2026-09-05T09:59:05.356Z","database_specific":{"cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86114.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86114.json"},{"type":"ADVISORY","url":"https://github.com/getarcaneapp/arcane/releases/tag/v2.0.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86114"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/arcane-before-2.0.0-missing-administrator-authorization-on-the-compose-template-mutation-endpoints"},{"type":"FIX","url":"https://github.com/getarcaneapp/arcane/commit/1500646aa91f"},{"type":"PACKAGE","url":"https://github.com/getarcaneapp/arcane"},{"type":"ARTICLE","url":"https://github.com/geo-chen/oss/blob/main/arcane.md"},{"type":"ARTICLE","url":"https://github.com/getarcaneapp/arcane/blob/v1.19.5/backend/api/handlers/templates.go"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getarcaneapp/arcane","events":[{"introduced":"02829b270b7975df32c8d5f787db7345dc6c27ac"},{"fixed":"2fb3931f6215b3e04f52432336665b8b68dfc990"}],"database_specific":{"extracted_events":[{"introduced":"1.19.1"},{"fixed":"2.0.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.20.0","types/v1.20.0","cli/v1.20.0","backend/v1.20.0","v1.19.5","types/v1.19.5","cli/v1.19.5","backend/v1.19.5","v1.19.4","types/v1.19.4","cli/v1.19.4","backend/v1.19.4","v1.19.3","types/v1.19.3","cli/v1.19.3","backend/v1.19.3","v1.19.2","types/v1.19.2","cli/v1.19.2","backend/v1.19.2","v1.19.1","types/v1.19.1","cli/v1.19.1","backend/v1.19.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86114.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}