Known CVE
Arcane < 1.18.0 - Unauthenticated Template and Env Disclosure
Arcane < 1.18.0 contains an information disclosure caused by missing authorization on /api/templates GET endpoints, letting unauthenticated network clients read sensitive Compose YAML and .env content, exploit requires network access
CVE-2026-42461
High2026CVSS 7.5CWE-306
cve2026 · arcane · exposure
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website