CVE-2026-106581
Received Received - Intake

Docker Desktop for Windows Signature Validation Bypass

Vulnerability report for CVE-2026-106581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Docker Inc.

Description

Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convince a user to approve the Docker-signed UAC prompt could execute attacker-controlled installer actions as LocalSystem.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Docker Docker Desktop 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Docker Desktop for Windows failing to verify the signature of a package provided to the Docker Desktop Installer.exe. An attacker could exploit this by creating a malicious package and tricking a user into approving a Docker-signed UAC prompt, allowing the attacker to execute arbitrary actions with LocalSystem privileges.

Detection Guidance

To detect this vulnerability, check the version of Docker Desktop installed on your system. Run 'docker version' or 'docker --version' in the command line. If the version is below 4.92.0, the system is vulnerable. Additionally, monitor for unexpected installer actions or UAC prompts during Docker Desktop updates.

Impact Analysis

If exploited, this vulnerability could allow an attacker to gain full control over your system with high privileges. This could lead to data theft, installation of malware, or complete system compromise. Users running vulnerable versions of Docker Desktop for Windows are at risk.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR and HIPAA. Organizations may face legal penalties, data breach notifications, and reputational damage if exploited.

Mitigation Strategies

Update Docker Desktop for Windows to version 4.92.0 or later to ensure package signature verification is enabled. Avoid using untrusted packages with Docker Desktop Installer.exe.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart