CSRF Vulnerability in Dockyard Docker Management App
CVE-2026-39848
6.5MEDIUM
What is CVE-2026-39848?
Dockyard, a Docker container management application, previously lacked proper CSRF protection for container start and stop operations, which were executed through GET requests. This design flaw allowed malicious actors to exploit a logged-in administrator's session by issuing unauthorized container actions via manipulated browser requests. The vulnerability has been rectified in version 1.1.0.
Affected Version(s)
dockyard < 1.1.0
