CVE-2026-40242Disclosure(getarcane / arcane)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. The server's response is returned directly to the caller. type. This constitutes an unauthenticated SSRF vulnerability affecting any publicly reachable Arcane instance. This vulnerability is fixed in 1.17.3.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • arcane

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-11); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
arcane

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-10: 1Mentions · 2026-04-11: 2Mentions · 2026-04-17: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-17: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 2Technical Details · 2026-04-17: 1Technical Details · 2026-04-28: 104-1004-1104-1704-28
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-101
Disclosure1
2026-04-112
Disclosure2
2026-04-171
Disclosure1
2026-04-281
Disclosure1
Full discourse5 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-40242 - high 🚨 Arcane <= 1.17.2 - Server-Side Request Forgery > Arcane <= 1.17.3 contains an unauthenticated server-side request forgery caused by la... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-40242 @pdnuclei #NucleiTemplates #cve

    Post summary

    Arcane versions up to 1.17.3 suffer from a high‑severity, unauthenticated server‑side request forgery vulnerability (CVE‑2026‑40242). A Nuclei template reference is provided for detection.

    00011141
    930 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Arcane, SSRF, #CVE-2026-40242 (High) https://dailycve.com/arcane-ssrf-cve-2026-40242-high/

    Post summary

    The tweet announces a high‑severity SSRF vulnerability (CVE‑2026‑40242) in Arcane and links to a DailyCVE article for further details.

    0001060
    181 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40242: CVE-2026-40242: Unauthenticated Server-Side Request Forgery in Arcane Template Fetch Mechanism Arcane, a web-based interface for managing Docker environments, contains a high-severity unauthenticated Server-Side Request Forgery (SSRF) ... https://cvereports.com/reports/CVE-2026-40242

    Post summary

    The post announces a newly disclosed unauthenticated SSRF vulnerability in Arcane, noting its high severity but providing no exploit evidence or mitigation details.

    0000026
    36 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40242 Unauthenticated Server-Side Request Forgery in Arcane Prior to 1.17.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40242

    Post summary

    A new unauthenticated SSRF vulnerability (CVE-2026-40242) affecting Arcane versions before 1.17.3 has been reported, with basic details provided and a link to a vulnerability database.

    0000046
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40242 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a caller-supplied url… https://www.cve.org/CVERecord?id=CVE-2026-40242

    Post summary

    The text references CVE‑2026‑40242 and describes a vulnerability in Arcane’s /api/templates/fetch endpoint that accepts a caller‑supplied URL, but it contains no information about PoC, exploitation, or patches.

    0000055
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetarcanearcane---

Explore more