Skip to content

Known CVE

Arcane < 1.18.0 - Unauthenticated Template and Env Disclosure

Arcane < 1.18.0 contains an information disclosure caused by missing authorization on /api/templates GET endpoints, letting unauthenticated network clients read sensitive Compose YAML and .env content, exploit requires network access

CVE-2026-42461

High2026CVSS 7.5CWE-306

cve2026 · arcane · exposure

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website