Skip to content
CC-4828

CC-4828

Digital.Nhs.Uk •[email protected] (NHS Digital) • August 11, 2026

CVE-2026-17106 could allow arbitrary file overwrite and potential code execution on systems running Docker commands

CVE-2026-17106 could allow arbitrary file overwrite and potential code execution on systems running Docker commands

The following platforms are known to be affected:

Public proof-of-concept exploit code for CVE-2026-17106

Public technical analysis and proof-of-concept details have been released describing how to exploit CVE-2026-17106 through the use of malicious containers and the docker cp command and the sbx cp command.

Docker has released security updates to address the vulnerability CVE-2026-17106 in Docker file copy functionality. Successful exploitation could allow an attacker to use a malicious container to create or overwrite arbitrary files on the host system and potentially achieve code execution with the privileges of the user running the Docker command.

Affected organisations are encouraged to review the Docker security updates associated with CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h and update Docker Engine, Docker CLI components, Docker Desktop, and Docker Sandboxes to the latest supported versions as soon as possible.

Last edited: 11 August 2026 4:01 pm