CVE-2026-92542
Received Received - Intake

Firewall Rule Bypass Enables VXLAN Encryption in Docker Swarm

Vulnerability report for CVE-2026-92542, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Docker Inc.

Description

The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
Docker Docker Engine 0
Docker Docker Engine 26.0.0
Docker Docker Engine overlay network driver 0
Docker Docker Engine overlay network driver v26.0.0
Moby Moby overlay network driver v2.0.0-beta.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Docker Engine's firewall rules incorrectly handling VXLAN datagrams. Legitimate VXLAN packets from the kernel and forged packets from user processes are treated the same way. An attacker on a Linux Swarm node can send UDP packets to the Swarm data-path port to inject fake Ethernet frames into an encrypted overlay network on another node.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized VXLAN traffic on the Swarm data-path port. Monitor UDP traffic to the Swarm data-path port (default 4789) using tools like tcpdump or Wireshark. Look for VXLAN headers with unexpected source IPs or payloads. Example command: tcpdump -i any udp port 4789 -nn -e -vv.

Impact Analysis

An unprivileged user on a Swarm node could inject malicious traffic into encrypted overlay networks, potentially compromising data integrity and availability. This could lead to unauthorized access, data leaks, or disruption of services relying on the overlay network.

Compliance Impact

This vulnerability could lead to unauthorized data exposure or tampering, violating confidentiality and integrity requirements in GDPR and HIPAA. Organizations using affected Docker versions may fail compliance audits if data is compromised due to this flaw.

Mitigation Strategies

Immediately upgrade Docker Engine to version 29.8.2 or later. As a temporary workaround, block userspace processes from sending UDP packets to the Swarm data-path port using iptables: iptables -A INPUT -p udp --dport 4789 -m owner --uid-owner 0 -j ACCEPT; iptables -A INPUT -p udp --dport 4789 -j DROP.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92542. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart