CVE-2026-53988

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-30: 109-30
Referenced assets1 URL
By indicator
Full discourse1 post
  • VulnTracker@vuln_tracker

    CVE-2026-53988 is a maximum severity flaw in Finsys's Dockhand, CVSS 10.0. A null webhook secret lets unauthenticated attackers force git clone and docker builds, and with write access to the tracked branch it escalates to container escape and full host takeover. VulnTracker recommends upgrading to Dockhand 1.0.40 immediately, this one needs no login at all. Details: http://vulntracker.io/cves/CVE-2026-53988 #Dockhand #CVE #InfoSec #DevOps

    0001031
    782 followersView on X

Explore more