CopyEscape Vulnerability in Docker Allows Host File Overwrites and Code Execution

CopyEscape Vulnerability in Docker Allows Host File Overwrites and Code Execution

First seen 11 Aug 2026, 20:12 UTC Digital.Nhs.UkRedditCybersecuritynews 81% similarity 69.0

Article Content

Browse articles
ThreatCluster

A newly disclosed vulnerability in Docker, tracked as CVE-2026-17106 and nicknamed 'CopyEscape', permits malicious containers to overwrite files on the host system and potentially achieve root code execution. The flaw affects the docker cp command and the sbx cp command, allowing attackers to exploit it through malicious containers. The vulnerability was discovered by the Imperva Red Team and has been assigned a high severity rating due to its potential impact on systems running Docker. Docker has released security updates to mitigate the risk associated with this vulnerability. Organizations using Docker are urged to update their systems to the latest versions immediately. Public proof-of-concept exploit code has also been released, increasing the urgency for remediation.

Key Points: • CVE-2026-17106, nicknamed 'CopyEscape', allows file overwrites and root access. • The vulnerability affects the docker cp and sbx cp commands in Docker. • Docker has released security updates; immediate action is recommended for affected users.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
CVE-2026-17106 disclosed
The vulnerability allows malicious containers to overwrite host files and gain root access, discovered by the Imperva Red Team.
Cybersecuritynews
2026-08-11
Docker releases security updates
Docker has issued updates to address CVE-2026-17106, urging users to upgrade their systems immediately.
Digital.Nhs.Uk

Community

Browse all →

Tracked Entities in This Story