« Volver al listado

CVE-2026-47179

Estado: AplazadaAlta (7.7)—

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before any path-traversal validation runs. Because ProjectService.CreateProject writes attacker-supplied compose content to disk without validating include paths, an authenticated user can create a project whose compose file declares include: ['../../../../etc/passwd'], then read the include via the project file API.

Leer descripción completaMostrar menos

The result is arbitrary read of any file readable by the Arcane backend process, including /app/data/arcane.db (the SQLite database containing every user's password hash and API key), enabling escalation to admin and, via Arcane's Docker control plane, RCE on the host. This vulnerability is fixed in 1.19.4.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso remoto con PR:L (usuario autenticado) a servicio interno (Docker backend); lectura arbitraria de archivos (/etc/passwd, arcane.db con hashes) y escalada admin vía credenciales robadas.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-47179",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-47179",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-02T15:44:09.404804Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "getarcaneapp",
          "product": "arcane",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.19.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-29T18:17:12.500",
  "references": [
    {
      "url": "https://github.com/getarcaneapp/arcane/commit/b6cbffabf61dbc3f12a28d3b5830e3c6b7e67daf",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/getarcaneapp/arcane/security/advisories/GHSA-c3px-h233-h6fq",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before any path-traversal validation runs. Because ProjectService.CreateProject writes attacker-supplied compose content to disk without validating include paths, an authenticated user can create a project whose compose file declares include: ['../../../../etc/passwd'], then read the include via the project file API. The result is arbitrary read of any file readable by the Arcane backend process, including /app/data/arcane.db (the SQLite database containing every user's password hash and API key), enabling escalation to admin and, via Arcane's Docker control plane, RCE on the host. This vulnerability is fixed in 1.19.4."
    },
    {
      "lang": "es",
      "value": "Arcane es una interfaz para gestionar contenedores Docker, imágenes, redes y volúmenes. Antes de la versión 1.19.4, ProjectService.GetProjectFileContent devuelve el contenido de cualquier directiva 'include' de Docker Compose declarada en el archivo compose de un proyecto antes de que se ejecute cualquier validación de recorrido de ruta. Debido a que ProjectService.CreateProject escribe contenido compose suministrado por el atacante en el disco sin validar las rutas de 'include', un usuario autenticado puede crear un proyecto cuyo archivo compose declara 'include': ['.. / .. / .. / ../etc/pass1d'], luego leer el 'include' a través de la API del archivo del proyecto. El resultado es la lectura arbitraria de cualquier archivo legible por el proceso backend de Arcane, incluyendo /app/data/arcane.db (la base de datos SQLite que contiene el hash de contraseña y la clave API de cada usuario), lo que permite la escalada a administrador y, a través del plano de control Docker de Arcane, RCE en el host. Esta vulnerabilidad está corregida en la versión 1.19.4."
    }
  ],
  "lastModified": "2026-07-25T10:10:00.167",
  "sourceIdentifier": "security-advisories@github.com"
}