PT-2026-31809 · Dockyard · Dockyard

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-39848

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dockyard versions prior to 1.1.0
Description Dockyard is a Docker container management app. Prior to version 1.1.0, Docker container start and stop operations are performed through GET requests without Cross-Site Request Forgery (CSRF) protection. An attacker can cause a logged-in administrator’s browser to send requests to API endpoints such as /apps/action.php?action=stop&name=<container> or /apps/action.php?action=start&name=<container>, potentially starting or stopping target containers. The vulnerable parameter is name.
Recommendations Update to version 1.1.0 or later.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-39848

Affected Products

Dockyard