top of page
perceptive_background_267k.jpg

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint ref…

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 19:07:04

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Web Technologies

CVE-2026-45627 affects Arcane, a Docker container management interface, prior to version 1.19.0. The vulnerability exists in an unauthenticated GET endpoint /api/app-images/logo that reflects user-supplied color parameters into SVG documents without proper escaping. Attackers can inject executable JavaScript content by closing style blocks and adding script tags. The lack of Content-Security-Policy and X-Content-Type-Options headers allows for cross-site scripting attacks. When a logged-in admin visits a crafted URL, the attacker can execute JavaScript in Arcane's origin and hijack the victim's HttpOnly JWT cookie, leading to full admin account compromise. This vulnerability has been fixed in version 1.19.0.

Technical details

Mitigation steps:

Affected products:

Arcane

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page