PT-2026-50676 · Docker · Docker Sandboxes

CVE-2026-12539

·

Published

2026-06-18

·

Updated

2026-08-13

CVSS v4.0

5.7

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Docker Sandboxes (affected versions not specified)
Description Docker Sandboxes (sbx) fail to re-apply the ICMP egress authorizer to networks rebuilt from disk after a Docker daemon restart. This allows a restart-surviving sandbox to forward ICMP traffic to arbitrary hosts, bypassing the documented egress block. An untrusted workload within the sandbox can exploit this to perform network reconnaissance or exfiltrate data via an ICMP covert channel, ignoring the configured allowlist.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12539

Affected Products

Docker Sandboxes