top of page
perceptive_background_267k.jpg

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents…

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 19:07:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Enterprise Applications

CVE-2026-47179 affects Arcane, a Docker container management interface, prior to version 1.19.4. The vulnerability allows authenticated users to exploit path traversal in Docker Compose include directives through ProjectService.GetProjectFileContent, which returns file contents before validation runs. Attackers can create malicious compose files with include paths like '../../../../etc/passwd' to read arbitrary files accessible to the Arcane backend process. This includes the SQLite database containing password hashes and API keys, enabling privilege escalation to admin and potential remote code execution on the host system through Arcane's Docker control plane. The issue is fixed in version 1.19.4.

Technical details

Mitigation steps:

Affected products:

Arcane

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page