top of page
perceptive_background_267k.jpg

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under…

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 21:09:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Identity & Access, Data Breach & Exfiltration

CVE-2026-45625 affects Arcane, a Docker container management interface, prior to version 1.19.0. The vulnerability stems from insufficient authorization checks in REST API endpoints managing GitOps repositories. Eight endpoints under /api/customize/git-repositories and /api/git-repositories/sync fail to call the checkAdmin(ctx) helper function. This allows any authenticated user with default user role to perform administrative operations including listing, creating, modifying, and deleting git repository configurations. Attackers can exploit this by redirecting repository URLs to attacker-controlled hosts, causing Arcane to decrypt and transmit legitimate PAT/SSH keys as plaintext credentials. The vulnerability enables one-step exfiltration of Git credentials and has been fixed in version 1.19.0.

Technical details

Mitigation steps:

Affected products:

Arcane

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page