logo

Critical 9.9 CVSS Flaw in Arcane Exposes GitOps Secrets to Basic Users

ID: 4f9250e3-b377-5265-95f7-a4543ac54503

STIX ID: report--4f9250e3-b377-5265-95f7-a4543ac54503

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

Arcane suffers a critical vulnerability (CVE-2026-45625, CVSS 9.9) where multiple GitOps REST endpoints fail to enforce admin checks, allowing any authenticated low-privileged user to read, modify, or delete repository configurations and to exfiltrate decrypted Git PATs/SSH keys by repointing repositories to attacker-controlled hosts; administrators are urged to upgrade to 1.19.0 immediately and rotate Git credentials if untrusted access occurred.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.