CVE-2026-105452
Awaiting Analysis Awaiting Analysis - Queue

Docker Sandbox Credential Forwarding Authentication Bypass

Vulnerability report for CVE-2026-105452, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Docker Inc.

Description

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Docker Docker Sandboxes 0.21.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy only removed alternate credentials when their values matched known sentinel values. This allowed untrusted code in an authorized sandbox to supply an unrecognized credential in another supported authentication header, potentially authenticating requests to an attacker-controlled account and exposing data in the request.

Impact Analysis

An attacker with access to an authorized sandbox could exploit this to authenticate requests as another user, potentially accessing sensitive data included in those requests. This could lead to unauthorized data exposure or account takeover if the affected service relies on the credentials for access control.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating confidentiality requirements in GDPR and HIPAA. Organizations using Docker Sandboxes may face compliance violations if sensitive data is exposed due to this flaw, potentially resulting in legal penalties or reputational damage.

Mitigation Strategies

Update Docker Sandboxes to the latest version to ensure the credential handling vulnerability is patched. Review sandbox network and filesystem policies in the Docker Admin Console to restrict untrusted code execution. Monitor Docker daemon logs for suspicious authentication attempts or unauthorized access patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105452. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart