Skip to main content

Docker Releases Security Updates for Docker Copy Functionality

CVE-2026-17106 could allow arbitrary file overwrite and potential code execution on systems running Docker commands

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2026-17106 could allow arbitrary file overwrite and potential code execution on systems running Docker commands


Threat details

Public proof-of-concept exploit code for CVE-2026-17106

Public technical analysis and proof-of-concept details have been released describing how to exploit CVE-2026-17106 through the use of malicious containers and the docker cp command and the sbx cp command.


Introduction

Docker has released security updates to address the vulnerability CVE-2026-17106 in Docker file copy functionality. Successful exploitation could allow an attacker to use a malicious container to create or overwrite arbitrary files on the host system and potentially achieve code execution with the privileges of the user running the Docker command.


Remediation advice

Affected organisations are encouraged to review the Docker security updates associated with CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h and update Docker Engine, Docker CLI components, Docker Desktop, and Docker Sandboxes to the latest supported versions as soon as possible.




Last edited: 11 August 2026 4:01 pm