


Perceptive Security
SOC/SIEM Consultancy

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint ref…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 19:07:04
Source:
nvd.nist.gov
Cloud & Virtualization, Web Technologies
CVE-2026-45627 affects Arcane, a Docker container management interface, prior to version 1.19.0. The vulnerability exists in an unauthenticated GET endpoint /api/app-images/logo that reflects user-supplied color parameters into SVG documents without proper escaping. Attackers can inject executable JavaScript content by closing style blocks and adding script tags. The lack of Content-Security-Policy and X-Content-Type-Options headers allows for cross-site scripting attacks. When a logged-in admin visits a crafted URL, the attacker can execute JavaScript in Arcane's origin and hijack the victim's HttpOnly JWT cookie, leading to full admin account compromise. This vulnerability has been fixed in version 1.19.0.
Technical details
Mitigation steps:
Affected products:
Arcane
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45627
https://github.com/getarcaneapp/arcane/security/advisories/GHSA-q2pj-8v84-9mh5
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
