/Vulnerability Library

Arcane < 1.18.0 - Unauthenticated Template and Env Disclosure

CVE-2026-42461
Verified

Description

Arcane < 1.18.0 contains an information disclosure caused by missing authorization on /api/templates GET endpoints, letting unauthenticated network clients read sensitive Compose YAML and .env content, exploit requires network access

Severity

High

CVSS Score

7.5

Exploit Probability

1%

Affected Product

arcane

Published Date

August 6, 2026

Template Author

str4k3r

CVE-2026-42461.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-42461
CWE ID:
cwe-306

References

https://github.com/getarcaneapp/arcane/security/advisories/GHSA-cxx3-hr75-4q96https://nvd.nist.gov/vuln/detail/CVE-2026-42461

Remediation Steps

Update to version 1.18.0 or later.