PT-2026-70252 · Docker · Docker

CVE-2026-17106

·

Published

2026-08-11

·

Updated

2026-09-08

CVSS v4.0

7.1

High

VectorAV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Docker (affected versions not specified)
Description An issue known as CopyEscape allows for an arbitrary file write from a container to the host system. This occurs through the use of the docker cp command, which can be leveraged to write files outside the intended container boundaries and onto the host machine.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97004
AZL-97007
BIT-DOCKER-CLI-2026-17106
CVE-2026-17106
GHSA-HFG8-HC9C-6C3H
GO-2026-6253
OESA-2026-3526
OPENSUSE-SU-2026:11544-1
OPENSUSE-SU-2026:21611-1
OPENSUSE-SU-2026:21761-1
SUSE-SU-2026:3863-1

Affected Products

Docker