THE Docker CopyEscape vulnerability, identified as CVE-2026-17106, allows attackers to exploit the 'docker cp' command, potentially leading to arbitrary file writes and code execution on host systems. This issue arises from timing gaps and validation flaws in Docker's file handling, particularly affecting versions prior to Docker Engine 29.7.2 and Docker Desktop 4.86.0. Patching is crucial; users are advised to upgrade affected versions or avoid using 'docker cp' in certain contexts to mitigate risks. The CVE carries a CVSS score of 7.1, reflecting its severity.
Docker CopyEscape bug lets attackers write files via docker cp
CyberSIXT Evidence Panel
Article by CyberSIXT