Skip to content
Critical Docker Vulnerability CVE-2026-17106 Allows Host File Overwrite

Critical Docker Vulnerability CVE-2026-17106 Allows Host File Overwrite

First seen 11 Aug 2026, 20:12 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 12, 2026 at 20:05 UTC
  • •CVE-2026-17106 allows arbitrary file overwrite and potential code execution.
  • •Affected systems include Docker Engine, CLI, Desktop, and Sandboxes.
  • •Public proof-of-concept exploit code has been released, increasing risk.

A critical vulnerability in Docker, identified as CVE-2026-17106 and dubbed 'CopyEscape', has been disclosed. This flaw allows malicious containers to overwrite files on the host system using the 'docker cp' command, potentially leading to code execution with the privileges of the user running the command. The vulnerability affects systems running Docker Engine, Docker CLI, Docker Desktop, and Docker Sandboxes. Public proof-of-concept exploit code has been released, raising concerns about active exploitation. Affected organizations are urged to update to the latest versions of Docker to mitigate risks. The flaw was discovered by the Imperva Red Team and is linked to unsafe symlink handling during extraction. Successful exploitation could compromise developer accounts or achieve root access. Security updates have been released to address this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 49d ago How this analysis works

Timeline

2026-08-11
CVE-2026-17106 disclosed
The vulnerability was publicly disclosed, allowing malicious containers to overwrite host files and potentially gain root access.
Digital.Nhs.Uk
2026-08-11
Public proof-of-concept released
Technical analysis and proof-of-concept details for exploiting CVE-2026-17106 were made public, raising concerns about active exploitation.
Reddit
2026-08-11
Docker releases security updates
Docker released updates for Docker Engine, CLI, Desktop, and Sandboxes to address CVE-2026-17106.
Cybersecuritynews
2026-08-12
Security advisory issued
Organizations using affected Docker versions are urged to update to the latest versions to mitigate the vulnerability.
Gbhackers

More articles in this cluster (4)

Following this threat?

Track CVE-2026-17106 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed