CVE-2026-28400Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime flags without authentication. These flags are passed directly to the underlying inference server (llama.cpp). By injecting the --log-file flag, an attacker with network access to the Model Runner API can write or overwrite arbitrary files accessible to the Model Runner process. When bundled with Docker Desktop (where Model Runner is enabled by default since version 4.46.0), it is reachable from any default container at model-runner.docker.internal without authentication. In this context, the file overwrite can target the Docker Desktop VM disk (`Docker.raw` ), resulting in the destruction of all containers, images, volumes, and build history. However, in specific configurations and with user interaction, it is possible to convert this vulnerability in a container escape. The issue is fixed in Docker Model Runner 1.0.16. Docker Desktop users should update to 4.61.0 or later, which includes the fixed Model Runner. A workaround is available. For Docker Desktop users, enabling Enhanced Container Isolation (ECI) blocks container access to Model Runner, preventing exploitation. However, if the Docker Model Runner is exposed to localhost over TCP in specific configurations, the vulnerability is still exploitable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-749

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 1 mentions (2026-02-28); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-28: 1Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-09-17: 1Patch / Workaround · 2026-09-17: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-09-17: 102-2803-0303-0403-0509-17
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-281
Disclosure1
2026-03-031
Disclosure1
2026-03-041
Disclosure1
2026-03-051
Disclosure1
2026-09-171
Patch1
Full discourse5 posts
  • Threat Landscape@LandscapeThreat
    Patch

    Docker disclosed two Docker Sandboxes vulnerabilities that can allow malicious guest environments to escape workspace isolation and access host resources. CVE-2026-77179, affecting macOS versions before 0.42.0, enables symlink-race redirection of filesystem operations, potentially permitting arbitrary file read/write and host code execution. CVE-2026-79994, affecting versions before 0.42.0, can redirect guest-to-host Unix socket connections to unauthorized AF_UNIX sockets, enabling data disclosure or access to host-side functions. Docker recommends upgrading to 0.42.0 or later, using clone mode, removing writable host mounts, and minimizing sensitive data in shared paths. VULNERABILITY CVE-2026-17106 CVE-2026-2664 CVE-2026-28400 CVE-2026-33990 CVE-2026-5817 CVE-2026-5843 CVE-2026-77179 CVE-2026-79994

    Post summary

    Docker disclosed two sandbox escape vulnerabilities with technical details and explicitly recommends upgrading to version 0.42.0 plus additional workarounds; no PoC, exploit tool, or active exploitation is reported.

    2004173
    98 followersView on X
  • Anonymous Tech@Anonymous_Tech7
    Disclosure

    Docker Desktop for Mac is vulnerable to a denial-of-service condition, CVE-2026-28400, via exposed Docker Model Runner, allowing local attackers to create a DoS condition with low-privileged code execution, rated 7.3 by ZDI.

    Post summary

    CVE‑2026‑28400 is a denial‑of‑service vulnerability in Docker Desktop for macOS via an exposed Docker Model Runner, permitting low‑privileged local code execution. No PoC, exploit tool, patch, or evidence of active exploitation is reported.

    0001045
    1 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Docker Desktop for Mac Docker Model Runner Exposed Dangerous Function Denial-of-Service Vulnerability (CVE-2026-28400) #CVE202628400 #CyberSecurity #Docker #DoSVulnerability https://www.systemtek.co.uk/?p=48625 https://t.co/9jA2JXNJxf

    Post summary

    The tweet announces the existence of CVE‑2026-28400, a Denial‑of‑Service flaw in Docker Desktop for Mac, but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000029
    1.8K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28400 (CVSS:7.5, HIGH) is Awaiting Analysis. Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 e..https://nvd.nist.gov/vuln/detail/CVE-2026-28400 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-28400, a high‑severity vulnerability in Docker Model Runner affecting versions before 1.0.16, with no PoC, exploit, or patch details provided.

    0000043
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28400 Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint … https://www.cve.org/CVERecord?id=CVE-2026-28400

    Post summary

    CVE-2026-28400 affects Docker Model Runner versions before 1.0.16, exposing a POST `/engines/_configure` endpoint that could be abused. No PoC, exploit, or patch details are provided in the text.

    00000143
    56.6K followersView on X

Explore more