THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86114 (MEDIUM 6.5) — Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or ho

[NVD] CVE-2026-86114 (MEDIUM 6.5) — Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or ho

mednvdPublished 2026-09-05

CVE-2026-86114 CVSS: 6.5 MEDIUM Published: 2026-09-05T10:16:42.423

Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative priv

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86114