


Perceptive Security
SOC/SIEM Consultancy

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoi…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 21:09:42
Source:
nvd.nist.gov
Cloud & Virtualization, Supply Chain & Dependencies, Identity & Access
A critical authorization bypass vulnerability in Arcane, a Docker container management interface, allows authenticated non-admin users to overwrite global environment variables via the PUT /api/environments/{id}/templates/variables endpoint. Attackers can exploit this to redirect image pulls to malicious registries, enabling supply-chain attacks and remote code execution on Docker hosts. The vulnerability also allows credential exfiltration and disruption of all projects by manipulating variables like REGISTRY, IMAGE, DATABASE_URL, and SECRET_KEY. This affects all versions prior to 1.19.2, which contains the fix.
Technical details
Mitigation steps:
Affected products:
Arcane
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-47125
https://github.com/getarcaneapp/arcane/security/advisories/GHSA-jpjh-jm2p-39hh
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
