CVE-2026-77179
Received Received - Intake

virtio-fs Symlink Following Arbitrary File Read in Docker Sandbox

Vulnerability report for CVE-2026-77179, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Docker Inc.

Description

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
docker docker *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects macOS systems using Docker Sandboxes. The virtio-fs host server improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

Impact Analysis

If exploited, this vulnerability could allow an attacker within a Docker Sandbox to access or modify sensitive files on the host system. This could lead to unauthorized data exposure, system compromise, or further attacks depending on the host's configuration and permissions.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating compliance requirements under GDPR, HIPAA, or other regulations. Organizations using Docker Sandboxes may face legal penalties, data breach notifications, and reputational damage if exploited.

Mitigation Strategies

Update Docker Sandboxes to the latest version immediately. Disable virtio-fs host server if not required. Restrict symlink access in shared workspaces. Monitor for unauthorized file access or modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77179. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart