CVE-2026-39848
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Apr 09, 2026
Vendor
unknown
Description
Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to request /apps/action.php?action=stop&name=<container> or /apps/action.php?action=start&name=<container>, which starts or stops the target container. This vulnerability is fixed in 1.1.0.