CVE-2026-23520 is a high-severity command injection vulnerability affecting Arcane Docker management software prior to version 1.13.0. It allows authenticated, non-administrative users to execute arbitrary shell commands within containers by crafting malicious lifecycle labels that are unsanitized and executed by the updater service. With a CVSS score of 8.0, this flaw presents a significant risk of full compromise (confidentiality, integrity, availability) once an administrator triggers an update. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered considerable community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.0CPE matchmatch criteria | cpe:2.3:a:arcane:arcane:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.