OVERVIEW CVE-2026-40242 is a Server-Side Request Forgery (SSRF) vulnerability in Arcane, a Docker container management interface. The flaw exists in the /api/templates/fetch endpoint, which processes an unauthenticated, caller-supplied URL parameter and executes server-side HTTP GET requests without validating the URL scheme, host, or requiring authentication. The vulnerability affects all versions of Arcane prior to 1.17.3 and impacts any publicly accessible instance. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) with a network-based attack vector that requires no authentication or user interaction. Attack complexity is low, making exploitation straightforward for remote actors. The vulnerability allows attackers to read server response data and potentially modify information through the compromised server connection, though system availability is not directly threatened. The FAUCET Risk Score of 45.0/100 indicates moderate organizational risk, and the EPSS score of 0.0152 suggests active exploitation is currently uncommon relative to other CVEs. EXPLOITATION STATUS There is no evidence of widespread active exploitation, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and appears inactive on threat intelligence watch lists. No public exploit code availability is noted in the provided data. Given the relatively low EPSS score and inactive status, community attention and exploitation activity appear minimal at present, though the vulnerability remains a legitimate concern for organizations running publicly exposed Arcane instances.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.3CPE matchmatch criteria | cpe:2.3:a:getarcane:arcane:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.