Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40242

34
FAUCET Score

OVERVIEW CVE-2026-40242 is a Server-Side Request Forgery (SSRF) vulnerability in Arcane, a Docker container management interface. The flaw exists in the /api/templates/fetch endpoint, which processes an unauthenticated, caller-supplied URL parameter and executes server-side HTTP GET requests without validating the URL scheme, host, or requiring authentication. The vulnerability affects all versions of Arcane prior to 1.17.3 and impacts any publicly accessible instance. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) with a network-based attack vector that requires no authentication or user interaction. Attack complexity is low, making exploitation straightforward for remote actors. The vulnerability allows attackers to read server response data and potentially modify information through the compromised server connection, though system availability is not directly threatened. The FAUCET Risk Score of 45.0/100 indicates moderate organizational risk, and the EPSS score of 0.0152 suggests active exploitation is currently uncommon relative to other CVEs. EXPLOITATION STATUS There is no evidence of widespread active exploitation, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and appears inactive on threat intelligence watch lists. No public exploit code availability is noted in the provided data. Given the relatively low EPSS score and inactive status, community attention and exploitation activity appear minimal at present, though the vulnerability remains a legitimate concern for organizations running publicly exposed Arcane instances.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.17.3CPE matchmatch criteria
cpe:2.3:a:getarcane:arcane:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.62%
Probability of exploitation in next 30 days
EPSS Percentile
46.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-40242 · Apr 17, 2026
This CVE's current EPSS score of 0.0062 is in the 29th percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/getarcaneapp/arcane/backendFixed in: 1.17.3
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-ff24-4prj-gpmjhigh

Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint

Apr 10, 2026

References

github.com / getarcaneapp/arcane/releases/tag/v1.17.3
Release Notes
github.com / getarcaneapp/arcane/security/advisories/GHSA-ff24-4prj-gpmj
ExploitVendor Advisory