CVE-2026-42306Disclosure(docker / engine)

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch docker engine systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • engine
  • moby
  • moby\/v2

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
enginemobymoby\/v2

1 version affected across 3 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-18: 2Patch / Workaround · 2026-05-18: 1Technical Details · 2026-05-18: 205-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Moby/Docker Container Escape Race Condition (CVE-2026-42306) A Time-of-Check to Time-of-Use (TOCTOU) race condition during docker cp operations allows a malicious container to redirect a bind mount to an arbitrary host path. By rapidly replacing the volume mount destination with a symlink before the mount() syscall executes, an attacker can overwrite critical files on the host system or mask host paths to cause a denial of service. 👉 Affected: http://github. com/docker/docker (<= 28.5.2), http://github. com/moby/moby (<= 28.5.2), http://github. com/moby/moby/v2 (< 2.0.0-beta.14) | Upgrade to moby/moby/v2 >= 2.0.0-beta.14

    Post summary

    A new container escape vulnerability (CVE-2026-42306) allows Docker containers to overwrite host files via a symlink race during docker cp. The issue is mitigated by upgrading to moby/moby/v2 version 2.0.0-beta.14 or later.

    0001190
    196 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 #Docker, Race Condition, #CVE-2026-42306 (High) https://dailycve.com/docker-race-condition-cve-2026-42306-high/

    Post summary

    The tweet announces a new high‑severity race condition vulnerability (CVE‑2026‑42306) affecting Docker.

    0000146
    206 followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
Appdockerengine---
Appmobyprojectmoby---
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--
Appmobyprojectmoby\/v22.0.0--

Explore more