


Perceptive Security
SOC/SIEM Consultancy

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 19:07:03
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access, Data Breach & Exfiltration
CVE-2026-45625 affects Arcane, a Docker container management interface, prior to version 1.19.0. The vulnerability allows any authenticated user to access admin-only GitOps repository management endpoints due to missing authorization checks. Eight of nine API endpoints under /api/customize/git-repositories and /api/git-repositories/sync fail to call the checkAdmin() function. Attackers can exploit this to list, create, modify, and delete git repository configurations. The most critical impact is credential exfiltration - attackers can redirect repository URLs to attacker-controlled hosts, causing Arcane to decrypt and send legitimate PAT/SSH keys as authentication, resulting in plaintext credential theft.
Technical details
Mitigation steps:
Affected products:
Arcane
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45625
https://github.com/getarcaneapp/arcane/security/advisories/GHSA-7h26-hg47-p9hx
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
