PT-2026-108908 · Docker · Docker Desktop For Windows

CVE-2026-106581

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v4.0

7.3

High

VectorAV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Docker Desktop for Windows versions prior to 4.92.0
Description The Docker Desktop Installer.exe fails to verify the signature of packages provided via the install -package command. This allows an attacker to execute arbitrary installer actions with LocalSystem privileges if they can provide a crafted package and persuade a user to approve the User Account Control (UAC) prompt.
Recommendations Update Docker Desktop for Windows to version 4.92.0 or later.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106581

Affected Products

Docker Desktop For Windows