Exposed Git Credentials Vulnerability in Arcane Management Interface
CVE-2026-45625
9.9CRITICAL
What is CVE-2026-45625?
The Arcane Management Interface, before version 1.19.0, contains a vulnerability in its huma-based REST API, exposing Git repository management endpoints without proper admin role checks. This issue allows any logged-in user, regardless of their role, to list, create, alter, or delete Git repository configurations. By manipulating repository URLs, an attacker can potentially extract plaintext Git credentials, including Personal Access Tokens (PAT) and SSH keys, during API calls. The flaw poses a significant risk to users and environments relying on Arcane for secure container management. Users are encouraged to upgrade to version 1.19.0 to mitigate this risk.
Affected Version(s)
arcane < 1.19.0
