CVE-2026-45625Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps source repositories and their stored credentials. Eight of those endpoints (list, create, get, update, delete, test, listBranches, browseFiles) never call the checkAdmin(ctx) helper that every other admin-managed resource (container registries, environments, users, API keys, swarm, settings, system, notifications, events) uses, and the huma authentication middleware deliberately enforces only authentication, not the admin role. As a result, any logged-in user with the default user role can list, create, modify, delete, and test git repository configurations. By repointing an existing repository's URL to an attacker-controlled host while omitting the token/sshKey fields (which UpdateRepository only rewrites when explicitly supplied), the attacker causes Arcane to decrypt the legitimate PAT/SSH key on its next /test, /branches, or /files call and present it as HTTP Basic auth (or SSH key auth) to the attacker's host — producing a one-step exfiltration of plaintext Git credentials. This vulnerability is fixed in 1.19.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-05-18); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-05-18: 2Mentions · 2026-05-20: 1Mentions · 2026-05-31: 2Mentions · 2026-06-19: 1Patch / Workaround · 2026-05-18: 2Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-20: 1Technical Details · 2026-05-31: 105-1805-2005-3106-19
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-182
Disclosure1Patch1
2026-05-201
Patch1
2026-05-312
Disclosure2
2026-06-191
General1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    Arcane fixes a critical 9.9 CVSS vulnerability (CVE-2026-45625) that allows basic users to steal GitOps credentials in plaintext. Update to 1.19.0! #Arcane #Docker #CVE #GitOps #CyberSecurity #InfoSec #VulnerabilityAlert #SupplyChainSecurity #DevSecOps https://securityonline.info/arcane-docker-management-vulnerability-cve-2026-45625-gitops-secrets-leak/ https://t.co/JJcs9bgJMB

    Post summary

    The tweet announces that Arcane has released a patch (version 1.19.0) for a critical 9.9 CVSS vulnerability (CVE-2026-45625) that exposed GitOps credentials in plaintext, but does not mention any PoC, exploit code, or active exploitation.

    01032383
    12.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Arcane Git Repository Authorization Bypass (CVE-2026-45625) Arcane <=1.18.1 improperly exposes Git repository management endpoints to any authenticated user, allowing low-privileged accounts to modify repository configurations, exfiltrate stored Git credentials, access private repository contents, and tamper with GitOps deployments. Successful exploitation may lead to credential theft, supply-chain compromise, and arbitrary deployment manipulation. 👉 Affected: Arcane <=1.18.1 | Fixed in: 1.19.0

    Post summary

    Arcane v1.18.1 and earlier expose Git repository endpoints to any authenticated user, enabling low‑privileged accounts to alter configs, exfiltrate credentials, and manipulate GitOps deployments – a potential credential theft and supply‑chain attack vector. The issue is fixed in v1.19.0.

    00020122
    255 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-45625 Arcane 1.19.0以前に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/06/13/cve-2026-45625-arcane-1190/ #IT #Security #cybersecurity

    Post summary

    The text links to a Japanese article announcing CVE-2026-45625 as a severe vulnerability in Arcane 1.19.0 or earlier, urging immediate response, but provides no further details about the flaw, exploitation, or mitigation.

    0001049
    209 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Arcane Backend Missing Authorization (CVE-2026-45625) A critical privilege escalation flaw in Arcane Backend allows low-privilege users to exfiltrate plaintext Git credentials and tamper with GitOps configurations. Because eight out of nine repository management endpoints fail to check for administrator rights, any authenticated user can change a repository's target URL to an attacker-controlled server. When Arcane next tests or syncs the repository, it automatically decrypts and sends the administrator's cleartext PAT or SSH key to the attacker. 👉 Affected: http://github.com/getarcaneapp/arcane/backend <= 1.18.1 | Upgrade to 1.19.0

    Post summary

    The post discloses a critical privilege escalation flaw in Arcane Backend that enables credential theft, and it recommends patching by upgrading to version 1.19.0.

    0001095
    196 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-45625 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/… https://www.cve.org/CVERecord?id=CVE-2026-45625 ----- Traducción: CVE-2026-45625 Arc… http://infoflow.cloud`

    Post summary

    A brief announcement of CVE-2026-45625, noting that Arcane's REST API exposes nine endpoints prior to version 1.19.0. No PoC, exploit, active exploitation, or patch information is provided.

    0000040
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45625 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/… https://www.cve.org/CVERecord?id=CVE-2026-45625

    Post summary

    The post briefly notes that CVE‑2026‑45625 involves Arcane’s REST API before version 1.19.0, exposing nine endpoints, but provides no exploitation details, patch information, or technical specifics.

    00000240
    57.6K followersView on X

Explore more