CVE-2026-39848
MEDIUMCVSS 6.5/10EPSS 0.21%
Last modified
This CVE is reserved or awaiting analysis. Details will appear once published by NVD.
Description
Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to request /apps/action.php?action=stop&name=<container> or /apps/action.php?action=start&name=<container>, which starts or stops the target container. This vulnerability is fixed in 1.1.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Are you affected by CVE-2026-39848?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
