Docker Releases Security Updates for Docker Copy Functionality
CVE-2026-17106 could allow arbitrary file overwrite and potential code execution on systems running Docker commands
Summary
CVE-2026-17106 could allow arbitrary file overwrite and potential code execution on systems running Docker commands
Affected platforms
The following platforms are known to be affected:
Threat details
Public proof-of-concept exploit code for CVE-2026-17106
Public technical analysis and proof-of-concept details have been released describing how to exploit CVE-2026-17106 through the use of malicious containers and the docker cp command and the sbx cp command.
Introduction
Docker has released security updates to address the vulnerability CVE-2026-17106 in Docker file copy functionality. Successful exploitation could allow an attacker to use a malicious container to create or overwrite arbitrary files on the host system and potentially achieve code execution with the privileges of the user running the Docker command.
Remediation advice
Affected organisations are encouraged to review the Docker security updates associated with CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h and update Docker Engine, Docker CLI components, Docker Desktop, and Docker Sandboxes to the latest supported versions as soon as possible.
Remediation steps
| Type | Step |
|---|---|
| Guidance |
GHSA-hfg8-hc9c-6c3h https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h |
| Patch |
Docker Sandboxes https://docs.docker.com/ai/sandboxes/release-notes/ |
| Patch |
Docker Desktop https://docs.docker.com/desktop/release-notes/#4860 |
| Patch |
Docker Engine/CLI https://docs.docker.com/engine/release-notes/29/ |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 11 August 2026 4:01 pm