PT-2026-36823 · Arcane · Arcane
Kmendell
·
Published
2026-04-30
·
Updated
2026-05-11
·
CVE-2026-42461
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Arcane versions prior to 1.18.0
Description
Four 'GET' endpoints under "/api/templates*" in the Huma backend are registered without security requirements. This authorization gap allows any unauthenticated network client to list and read the full Compose YAML and
.env content of every custom template stored in the instance. Because the user interface persists real environment content—such as database passwords and API keys—verbatim during the "Save as Template" flow, this allows for the unauthenticated read of operator secrets. The affected endpoints include "/templates", "/templates/all", "/templates/{id}", and "/templates/{id}/content".Recommendations
Update to version 1.18.0.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcane