


Perceptive Security
SOC/SIEM Consultancy

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoi…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 19:07:03
Source:
nvd.nist.gov
Cloud & Virtualization, Supply Chain & Dependencies, Identity & Access
Arcane, a Docker container management interface, contains a critical authorization bypass vulnerability in version prior to 1.19.2. The PUT /api/environments/{id}/templates/variables endpoint lacks proper admin authorization checks, allowing any authenticated non-admin user to overwrite global environment variables. Attackers can exploit this to redirect image pulls to malicious registries, enabling supply-chain attacks and remote code execution on Docker hosts. The vulnerability also allows credential exfiltration and service disruption across all projects. This represents a significant supply chain risk in containerized environments.
Technical details
Mitigation steps:
Affected products:
Arcane
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-47125
https://github.com/getarcaneapp/arcane/security/advisories/GHSA-jpjh-jm2p-39hh
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
