THREAT OPS › Threat News › [NVD] CVE-2026-86114 (MEDIUM 6.5) — Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or ho
[NVD] CVE-2026-86114 (MEDIUM 6.5) — Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or ho
CVE-2026-86114 CVSS: 6.5 MEDIUM Published: 2026-09-05T10:16:42.423
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative priv
Indicators of compromise
- CVE-2026-86114cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86114