getarcaneapp has 3 CVEs on record. 1 was published in the last 90 days. The median CVSS is 7.2 (high). Most affected products: github.com/getarcaneapp/arcane/backend (2), arcane (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Weakness classes
Products
- github.com/getarcaneapp/arcane/backend 2
- arcane 1
Worst active — by depth score
CVE-2026-40242High· 7.2Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint52CVE-2026-47179High· 7.7Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives42CVE-2026-86114Medium· 6.5Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults36
getarcaneapp vulnerabilities
CVEs affecting getarcaneapp, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-86114Medium· 6.5Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container co…
CVE-2026-47179High· 7.7Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives
CVE-2026-40242High· 7.2PoCArcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint