Vulnerabilidades em getarcaneapp
10 resultadosAnálise Vexday
A getarcaneapp apresenta 9 vulnerabilidades catalogadas, com 6 publicadas nos últimos 90 dias, indicando atividade recente de descoberta. Nenhuma vulnerabilidade está sob ataque ativo no momento, reduzindo o risco imediato, mas 2 são críticas e a fraqueza dominante (CWE-862 - falta de autorização) aponta para problemas estruturais em controle de acesso. O padrão de descobertas recentes recomenda acompanhamento próximo do fornecedor.
CVE-2026-23520CRITICALArcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCEEPSS 1.9%CVE-2026-42461HIGHArcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets)EPSS 1.3%CVE-2026-40242HIGHArcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch EndpointEPSS 0.6%CVE-2026-23944HIGHArcane allows unauthenticated proxy access to remote environmentsEPSS 0.5%CVE-2026-45625CRITICALArcane: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configsEPSS 0.4%CVE-2026-47179HIGHArcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in ArcaneEPSS 0.3%CVE-2026-47125HIGHArcane: Missing admin authorization on global variables endpointEPSS 0.2%CVE-2026-86114HIGHArcane before 2.0.0 Missing Administrator Authorization on the Compose Template Mutation EndpointsEPSS 0.2%CVE-2026-45626MEDIUMArcane: OS Command Injection in Volume Browser ListDirectory via path query parameterEPSS 0.2%CVE-2026-45627HIGHArcane: Unauthenticated reflected XSS via SVG color parameter in /api/app-images/logo enables admin account takeoverEPSS 0.2%