目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1310

100%

CVE-2026-45625— Arcane 仓库接口越权漏洞

CVSS 9.9 · Critical

可能的 ATT&CK 技术 1AI

T1530 · Data from Cloud Storage

影响版本矩阵 1

厂商产品版本范围状态
getarcaneapparcane< 1.19.0affected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-45625 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Arcane: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps source repositories and their stored credentials. Eight of those endpoints (list, create, get, update, delete, test, listBranches, browseFiles) never call the checkAdmin(ctx) helper that every other admin-managed resource (container registries, environments, users, API keys, swarm, settings, system, notifications, events) uses, and the huma authentication middleware deliberately enforces only authentication, not the admin role. As a result, any logged-in user with the default user role can list, create, modify, delete, and test git repository configurations. By repointing an existing repository's URL to an attacker-controlled host while omitting the token/sshKey fields (which UpdateRepository only rewrites when explicitly supplied), the attacker causes Arcane to decrypt the legitimate PAT/SSH key on its next /test, /branches, or /files call and present it as HTTP Basic auth (or SSH key auth) to the attacker's host — producing a one-step exfiltration of plaintext Git credentials. This vulnerability is fixed in 1.19.0.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
授权机制缺失
来源: 美国国家漏洞数据库 NVD

受影响产品

厂商产品影响版本CPE订阅
getarcaneapparcane < 1.19.0 -

二、漏洞 CVE-2026-45625 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-45625 的情报信息

登录查看更多情报信息。

CVE-2026-45625 厂商安全公告 (1)

同批安全公告 · getarcaneapp · 2026-05-29 · 共 5 条

CVE-2026-471258.8 HIGHArcane 全局变量端点管理权限缺失漏洞
CVE-2026-456278.2 HIGHArcane /api/app-images/logo未授权反射型XSS致管理员账户接管
CVE-2026-471797.7 HIGHArcane通过Docker Compose包含指令实现已验证的任意主机文件读取漏洞
CVE-2026-456266.3 MEDIUMArcane 体积浏览器列表目录命令注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-45625

暂无评论


发表评论