A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-45625

CVE-2026-45625: Arcane Docker Manager Auth Bypass Flaw

CVE-2026-45625 is an authentication bypass vulnerability in Arcane Docker management interface that lets non-admin users access GitOps endpoints and exfiltrate Git credentials. This article covers technical details, affected versions, and patches.

Published: June 4, 2026

CVE-2026-45625 Overview

CVE-2026-45625 is a missing authorization vulnerability [CWE-862] in Arcane, an interface for managing Docker containers, images, networks, and volumes. Versions prior to 1.19.0 expose nine GitOps repository management endpoints under /api/customize/git-repositories and /api/git-repositories/sync without administrative role checks. Any authenticated user with the default user role can list, create, modify, delete, and test Git repository configurations. An attacker can repoint an existing repository to an attacker-controlled host and force Arcane to decrypt and transmit stored Personal Access Tokens (PATs) or SSH keys. The vulnerability is fixed in version 1.19.0.

Critical Impact

Authenticated low-privileged users can exfiltrate plaintext Git credentials stored by Arcane in a single API request, compromising connected source code repositories.

Affected Products

  • Arcane versions prior to 1.19.0
  • Arcane huma-based REST API GitOps endpoints
  • Arcane stored Git PAT and SSH key credentials

Discovery Timeline

  • 2026-05-29 - CVE-2026-45625 published to the National Vulnerability Database (NVD)
  • 2026-05-29 - Last updated in NVD database

Technical Details for CVE-2026-45625

Vulnerability Analysis

Arcane's huma-based REST API exposes nine endpoints for managing GitOps source repositories and their associated credentials. Eight of those endpoints — list, create, get, update, delete, test, listBranches, and browseFiles — fail to invoke the checkAdmin(ctx) helper used by every other admin-managed resource. Other resources such as container registries, environments, users, API keys, swarm, settings, system, notifications, and events all enforce administrative authorization. The huma authentication middleware enforces only authentication and intentionally does not enforce role-based access.

The vulnerability allows any logged-in user with the default user role to manipulate stored GitOps repository configurations. Because repositories store Personal Access Tokens and SSH keys for upstream Git providers, manipulation of these records exposes credentials that often grant broad access to source code, CI/CD pipelines, and downstream production systems.

Root Cause

The root cause is a missing authorization check [CWE-862] on GitOps endpoints. The UpdateRepository handler rewrites the stored token and sshKey fields only when they are explicitly supplied in the request body. An attacker can update the repository URL while omitting credential fields, leaving the encrypted credentials intact but now bound to a hostile remote.

Attack Vector

An authenticated low-privileged user issues an update request against an existing repository, replacing the upstream URL with an attacker-controlled host and omitting token and sshKey. On the next call to /test, /branches, or /files, Arcane decrypts the stored PAT or SSH key and presents it as HTTP Basic authentication or SSH key authentication against the attacker's host. The attacker captures the plaintext credential in a single round trip, with no additional user interaction required.

No verified public exploit code is available. See the GitHub Security Advisory for the vendor's technical write-up.

Detection Methods for CVE-2026-45625

Indicators of Compromise

  • Outbound HTTPS or SSH connections from Arcane hosts to Git endpoints that do not match the organization's approved source forges.
  • Modifications to records in the git_repositories table where the url field changes but token and sshKey ciphertext remain unchanged.
  • API calls to /api/customize/git-repositories or /api/git-repositories/sync originating from sessions bound to non-admin users.
  • Bursts of /test, /branches, or /files requests immediately following a repository update event.

Detection Strategies

  • Audit Arcane access logs for write operations against /api/customize/git-repositories/* issued by accounts without the admin role.
  • Correlate repository update events with subsequent test or sync calls to identify the credential-decryption trigger pattern.
  • Inspect egress traffic from the Arcane host for connections to unexpected destinations on TCP 443 and 22.

Monitoring Recommendations

  • Enable verbose audit logging on the Arcane API and forward events to a centralized log platform for retention and review.
  • Alert on any change to url fields in stored Git repository records and require operator confirmation.
  • Rotate stored Git PATs and SSH keys on any anomalous repository modification and review upstream Git provider audit logs for unauthorized clones or pulls.

How to Mitigate CVE-2026-45625

Immediate Actions Required

  • Upgrade Arcane to version 1.19.0 or later, which adds the missing checkAdmin(ctx) enforcement on GitOps endpoints.
  • Rotate every Git Personal Access Token and SSH key stored in Arcane, treating prior credentials as exposed.
  • Review upstream Git provider audit logs for unauthorized authentication attempts originating from unexpected source IPs.
  • Restrict the Arcane user base to trusted operators until the upgrade is applied.

Patch Information

The vendor fixed the vulnerability in Arcane 1.19.0. The patch adds administrative authorization checks to all GitOps repository endpoints. Refer to the GitHub Security Advisory GHSA-7h26-hg47-p9hx for vendor guidance and release details.

Workarounds

  • Place Arcane behind a reverse proxy that blocks /api/customize/git-repositories and /api/git-repositories/sync for non-administrator sessions until upgrade.
  • Remove all stored Git credentials from Arcane and use ephemeral, scoped tokens supplied at sync time where feasible.
  • Disable or remove non-admin user accounts on Arcane instances that cannot be upgraded immediately.
bash
# Example reverse proxy rule to block GitOps endpoints pending upgrade
location ~ ^/api/(customize/git-repositories|git-repositories/sync) {
    return 403;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechArcane

  • SeverityCRITICAL

  • CVSS Score9.9

  • EPSS Probability0.05%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-862
  • Technical References
  • GitHub Security Advisory
  • Related CVEs
  • CVE-2026-23944: Arcane Docker Manager Auth Bypass Flaw

  • CVE-2026-45626: Arcane Docker Management RCE Vulnerability

  • CVE-2026-45627: Arcane Docker Manager XSS Vulnerability

  • CVE-2026-47179: Arcane Path Traversal Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English