CVE-2026-17106 could allow arbitrary file overwrite and potential code execution on systems running Docker commands
CVE-2026-17106 could allow arbitrary file overwrite and potential code execution on systems running Docker commands
The following platforms are known to be affected:
Public proof-of-concept exploit code for CVE-2026-17106
Public technical analysis and proof-of-concept details have been released describing how to exploit CVE-2026-17106 through the use of malicious containers and the docker cp command and the sbx cp command.
Docker has released security updates to address the vulnerability CVE-2026-17106 in Docker file copy functionality. Successful exploitation could allow an attacker to use a malicious container to create or overwrite arbitrary files on the host system and potentially achieve code execution with the privileges of the user running the Docker command.
Affected organisations are encouraged to review the Docker security updates associated with CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h and update Docker Engine, Docker CLI components, Docker Desktop, and Docker Sandboxes to the latest supported versions as soon as possible.
Last edited: 11 August 2026 4:01 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
