Exposed Git Credentials Vulnerability in Arcane Management Interface
CVE-2026-45625

9.9CRITICAL

Key Information:

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45625?

The Arcane Management Interface, before version 1.19.0, contains a vulnerability in its huma-based REST API, exposing Git repository management endpoints without proper admin role checks. This issue allows any logged-in user, regardless of their role, to list, create, alter, or delete Git repository configurations. By manipulating repository URLs, an attacker can potentially extract plaintext Git credentials, including Personal Access Tokens (PAT) and SSH keys, during API calls. The flaw poses a significant risk to users and environments relying on Arcane for secure container management. Users are encouraged to upgrade to version 1.19.0 to mitigate this risk.

Affected Version(s)

arcane < 1.19.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.