CVE-2026-23520·Docker vulnerability
Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update that allowed defining a command to run before or after a container update. The label value is passed directly to /bin/sh -c without sanitization or validation. Because any authenticated user (not limited to administrators) can create projects through the API, an attacker can create a project that specifies one of these lifecycle labels with a malicious command. When an administrator later triggers a container update (either manually or via scheduled update checks), Arcane reads the lifecycle label and executes its value as a shell command inside the container. This vulnerability is fixed in 1.13.0.
- Severity
- critical
- Software
- Docker
- Fixed in
- 1.13.0
- Published
- 2026-01-15
Affected versions
Until: 1.13.0
Fixed in: 1.13.0
How to fix this CVE
Upgrade Docker to version 1.13.0 or later to patch a critical command injection vulnerability in the Arcane updater service. The vulnerability allows authenticated users to inject arbitrary shell commands through container lifecycle labels that are executed without sanitization when administrators trigger container updates. Immediate patching is essential to prevent privilege escalation and remote code execution within containerized environments.
sudo dnf update docker-ce --assumeyesDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
shell_command_injection_in_container_labels: (com\.getarcaneapp\.arcane\.lifecycle\.(pre|post)-update.*[;&|`$(){}\[\]<>]|/bin/sh -c.*exec|bash -c.*'.*&&.*')How to check if you are affected
- Check installed Docker version: docker --version or docker version | grep Version
- List all container labels with potential lifecycle hooks: docker inspect $(docker ps -aq) | grep -A5 'com.getarcaneapp.arcane.lifecycle'
- Search Docker daemon logs for shell command execution patterns: sudo grep -E '(pre-update|post-update|/bin/sh -c)' /var/log/docker.log or journalctl -u docker --no-pager | grep -i 'lifecycle'
- Verify the patched version is running: docker version --format '{{.Server.Version}}' and confirm it is 1.13.0 or higher
FAQ
What is CVE-2026-23520?
CVE-2026-23520 is a critical command injection vulnerability in Arcane (a Docker management tool) that allows authenticated users to execute arbitrary shell commands on containers by injecting malicious payloads into lifecycle label definitions that are processed unsanitized during container updates.
Is CVE-2026-23520 being actively exploited?
No, CVE-2026-23520 is not currently listed on the CISA KEV catalog and no public exploits are available, but the critical CVSS score of 9.0 and ease of exploitation warrant immediate patching.
What versions of Docker are affected by CVE-2026-23520?
All versions of Docker prior to 1.13.0 are affected by this vulnerability when using Arcane's updater service with lifecycle label processing.
How do I check if my server is vulnerable to CVE-2026-23520?
Run 'docker version --format "{{.Server.Version}}"' and compare the version against 1.13.0; if your version is earlier than 1.13.0, your deployment is vulnerable.
Does Defensia detect CVE-2026-23520?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2026-23520 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-23520. Free for 1 server.
Get started free