Vulnerability Description
Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to request /apps/action.php?action=stop&name=<container> or /apps/action.php?action=start&name=<container>, which starts or stops the target container. This vulnerability is fixed in 1.1.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/10ij/dockyard/security/advisories/GHSA-jrf6-3j4j-q36g
- https://github.com/10ij/dockyard/security/advisories/GHSA-jrf6-3j4j-q36g
FAQ
What is CVE-2026-39848?
CVE-2026-39848 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logg...
How severe is CVE-2026-39848?
CVE-2026-39848 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-39848?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.