Arcane < 1.18.0 - Unauthenticated Template and Env Disclosure
CVE-2026-42461
Verified
Description
Arcane < 1.18.0 contains an information disclosure caused by missing authorization on /api/templates GET endpoints, letting unauthenticated network clients read sensitive Compose YAML and .env content, exploit requires network access
Severity
High
CVSS Score
7.5
Exploit Probability
1%
Affected Product
arcane
Published Date
August 6, 2026
Template Author
str4k3r
CVE-2026-42461.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-42461
CWE ID:
cwe-306
Remediation Steps
Update to version 1.18.0 or later.