CVE-2026-42461Disclosure(getarcane / arcane)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/templates* in Arcane's Huma backend are registered without any Security requirement, allowing any unauthenticated network client to list and read the full Compose YAML and .env content of every custom template stored in the instance. Because Arcane's UI exposes a "Save as Template" flow on the project / swarm-stack creation pages that persists the operator's real env content (database passwords, API keys, etc.) verbatim, this missing authorization is an unauthenticated read of operator secrets in practice — not a theoretical info-disclosure. The frontend explicitly treats /customize/templates/* as an authenticated area (PROTECTED_PREFIXES in frontend/src/lib/utils/redirect.util.ts), and every CRUD operation (POST/PUT/DELETE) on the same paths requires a Bearer/API key, so this is a clear backend authorization gap, not intended public access. This issue has been patched in version 1.18.0.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • arcane

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-09); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
arcane

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-09: 2Mentions · 2026-05-11: 1Mentions · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-11: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-11: 1Technical Details · 2026-08-11: 105-0905-1108-11
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-092
Disclosure1General1
2026-05-111
Disclosure1
2026-08-111
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-42461 - high 🚨 Arcane < 1.18.0 - Unauthenticated Template and Env Disclosure > Arcane < 1.18.0 contains an information disclosure caused by missing authorization on... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-42461 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE-2026-42461 as a high‑severity vulnerability affecting Arcane versions below 1.18.0, describing an unauthenticated information disclosure due to missing authorization. It includes a link to a detection template but no exploit code or patch information.

    030102651
    1.3K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-42461 📊 Severity: 8.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42461 #CVE-2026-42461 #CVE #High #CyberSecurity #InfoSec https://t.co/BVAH6mNJIn

    Post summary

    The post announces CVE‑2026‑42461 with a severity score of 8.7 and high risk, but provides no PoC, exploit, or patch details.

    0000043
    157 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42461 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/templates* in Arcane's Hu… https://www.cve.org/CVERecord?id=CVE-2026-42461

    Post summary

    The text references CVE-2026-42461 and notes unsecured GET endpoints in Arcane before version 1.18.0, but offers no actionable exploit, patch, or claim of active usage.

    0000066
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42461 Unauthenticated Information Disclosure of Secrets in Arcane Docker Manag... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42461 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE‑2026‑42461, an unauthenticated information disclosure vulnerability in Arcane Docker Manager, but offers no PoC, exploit details, active exploitation evidence, patch info, or technical specifics.

    0000053
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetarcanearcane---

Explore more