CVE-2026-58455Disclosure

MEDIUMCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php. Attackers can seed the required session flag through the incomplete auth check, then inject arbitrary commands via the composePath POST parameter in the composePull action to achieve full host compromise, facilitated by the standard deployment mounting of the Docker socket.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-698

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 12 signals
  • Disclosure: 6 classified signals
  • Peaked 8d ago at 3 mentions (2026-07-02); latest day: 1
  • 14 total mentions across 9 days

Deep dive

Activity timeline14 mentions / 9d
01223Mentions · 2026-07-02: 3Mentions · 2026-07-03: 2Mentions · 2026-07-06: 1Mentions · 2026-07-07: 2Mentions · 2026-07-21: 1Mentions · 2026-07-22: 1Mentions · 2026-07-23: 1Mentions · 2026-07-24: 2Mentions · 2026-08-04: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-21: 1Exploit Tool / Code · 2026-07-07: 2Exploit Tool / Code · 2026-07-21: 1Exploit Tool / Code · 2026-07-24: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-02: 3Technical Details · 2026-07-03: 2Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 2Technical Details · 2026-07-21: 1Technical Details · 2026-07-23: 1Technical Details · 2026-07-24: 1Technical Details · 2026-08-04: 107-0207-0307-0607-0707-2107-2207-2307-2408-04
Signal classification4 categories
Disclosure
642.9%
Exploit
428.6%
Patch
214.3%
General
214.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-07-023
Disclosure2Patch1
2026-07-032
Disclosure1Patch1
2026-07-061
Disclosure1
2026-07-072
Exploit2
2026-07-211
Exploit1
2026-07-221
Disclosure1
2026-07-231
Disclosure1
2026-07-242
Exploit1General1
2026-08-041
General1
Full discourse14 posts
  • kmkz@kmkz_security
    Disclosure

    Fun story: a self-hosted #Docker container manager, official image,standard config, docker.sock mounted exactly like every setup guide tells you to. Preauth. RCE + confirmed container escape to host on default config... and still currently unpatched ! CVE-2026-58455 / CVSS 9.8. Two bugs chained as "#0day" exploit: 1 - loader.php keeps processing after an auth redirect, no exit() 2 - ajax/compose.php feeds composePath straight into shell_exec() RCE in the container -> straight out to the host through the socket the app needs to do its job 👌 "Container escapes are usually bad admin config", they say. W00T ? Here we have an official image, default docker-compose, zero tuning => Perfect counterexample ! So why this .gif clip ? 👉because this is genuinely that easy to reach+ it illustrates, one more time, why focusing on patch mgmt is a huge mistake in 2026 ! You said "0-day" exploit ? Yep: No fix merged yet; the researcher's own patch (PR #135) was closed by the maintainer, folded into unrelated upcoming changes, *no ETA given*. PoC and full chain withheld until an actual fix ships. Not every exploited bug is patchable on day one. > Assume breach is the mindset, not the panic button. No public exploit does not mean not exploitable 🔥 + Remember: #Docker != secure, even with a team actively maintaining the product. Advisory by @VulnCheckAI : https://www.vulncheck.com/advisories/dockwatch-unauthenticated-os-command-injection-via-ajax-compose-php Credit: rayyb0t (https://github.com/rayyb0t)

    Post summary

    The post announces an unpatched pre‑auth RCE in a Docker container manager (CVE‑2026‑58455) with detailed vulnerability description, but no PoC, exploit code, or active exploitation evidence is provided.

    2101482510.5K
    19.8K followersView on X
  • kmkz@kmkz_security
    Exploit

    Released the full lab material used for this Dockwatch demo: Docker Compose environment, exploit script, reproduction notes and demo files. CVE-2026-58455 chains an authentication bypass with command injection. In the standard deployment, RCE inside the application container becomes host compromise through the mounted Docker socket. The proposed fix in PR #135 was closed without merge: https://github.com/Notifiarr/dockwatch/pull/135 The maintainer said the issues would be addressed in upcoming changes, but v0.6.567 remains the latest public release. At this point, this is a public, unpatched 1-day. > Given how trivial the chain is, there is little value in keeping the reproducer private. If you operate Dockwatch with docker.sock mounted, you should be able to test your own deployment. Material: https://github.com/kmkz/Exploits/tree/master/2026/CVE-2026-58455-Dockwatch

    Post summary

    The post reveals that CVE-2026-58455, an authentication bypass exploiting command injection to achieve RCE through a Docker socket, is publicly demonstrable with full lab material, though no patch exists yet.

    05021204.6K
    19.8K followersView on X
  • YogSotho@YogSoth0
    Exploit

    #CVE-2026-58455 #DockWatch #RCE #Exploit Kit ## Overview This toolkit exploits an **unauthenticated OS command injection** vulnerability in **DockWatch ≤ v0.6.567**. Vulnerability Details CVE: CVE-2026-58455 CVSS: 10.0 (Critical) Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Versions: DockWatch ≤ 0.6.567 #0days #security #cybersecurity #cybernews #hacking #antisec #infosec #python #antisec #infosec

    Post summary

    An exploit kit targeting DockWatch v0.6.567 via unauthenticated OS command injection has been disclosed with detailed vulnerability attributes, though no PoC or active exploitation evidence is provided.

    110111550
    1.9K followersView on X
  • ET Labs@ET_Labs
    General

    17 new OPEN, 18 new PRO (17 + 1) CVE-2026-1705 (Red hat Keycloak PII Disclosure), CVE-2026-58455 (Dockwatch compose.php composePath Command Injection), LandUpdate808, TA569, ZPHP, and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-08-04-v11249/3408

    Post summary

    The note lists 17 new OPEN and 18 new PRO CVEs, providing minimal technical descriptors but no PoC, exploitation details, patches, or evidence of active use.

    02010257
    5.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-58455 - critical 🚨 Dockwatch <= 0.6.567 - OS Command Injection > Dockwatch through 0.6.567 contains an unauthenticated command injection caused by mis... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-58455 @pdnuclei #NucleiTemplates #cve

    Post summary

    This tweet discloses a critical OS command injection vulnerability in Dockwatch versions ≤0.6.567, linking to a Project DisDiscovery library entry for details, but it does not provide a PoC, exploit code, evidence of active exploitation, or patch information.

    00011215
    1.1K followersView on X
  • YogSotho@YogSoth0
    Exploit

    @kmkz_security # CVE-2026-58455 DockWatch RCE Exploit Kit ## Overview This toolkit exploits an **unauthenticated OS command injection** vulnerability in **DockWatch ≤ v0.6.567** https://t.co/XI1gZUig1o

    Post summary

    The tweet announces a new exploit kit that targets DockWatch’s unauthenticated OS command injection flaw (CVE-2026-58455) specifically for versions up to 0.6.567, with no discussion of active use or patching.

    10010118
    1.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    Vendor vv0.6.567. Source: X search for vulnerability critical 2026 Posted: 2026-07-07T10:40:54.000Z Likes: 11 #CVE-2026-58455 #DockWatch #RCE #Exploit Kit Overview This toolkit exploits an unauthenticated OS command injection vulnerability in DockWatch ≤ v0.6.567.

    Post summary

    The tweet announces an exploit toolkit for CVE-2026-58455, an unauthenticated OS command injection in DockWatch up to version 0.6.567, without reporting active exploitation or patch availability.

    1000067
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-58455. Source: X search for vulnerability critical 2026 Posted: 2026-07-07T10:40:54.000Z Likes: 11

    Post summary

    The tweet merely lists a CVE identifier with no further details or context.

    1000068
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    12:13 UTC: CVE-2026-58455 disclosed. Fun story: a self-hosted #Docker container manager, official image,standard config, docker.sock mounted exactly like ev

    Post summary

    The message announces the disclosure of CVE‑2026‑58455, noting it involves a Docker container manager with a docker.sock mounting configuration.

    1000037
    326 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-58455 — CVSS 9.8/10 ██████████ Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/IjOUmWjTG0

    Post summary

    The tweet announces a critical unauthenticated OS command injection vulnerability (CVE‑2026‑58455) in Dockwatch with a CVSS score of 9.8, and urges users to apply the available patch.

    1000062
    63 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2026-58455: Critical Dockwatch RCE via Unauthenticated Command Injection — … "A critical vulnerability designated CVE-2026-58455 (CVSS 9.8) has been disclosed in…" 🔗 https://securityarsenal.com/blog/cve-2026-58455-critical-dockwatch-rce-via-unauthenticated-command-injection-detection-and-hardening #CyberSecurity #ThreatIntel #cve202658455 #critical #cve

    Post summary

    CVE-2026-58455, a critical remote‑code‑execution flaw in Dockwatch, has been disclosed with a CVSS score of 9.8; the linked blog outlines detection and hardening steps but no PoC, exploit code, or evidence of active exploitation is provided.

    0000062
    18 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Dockwatch Unauthenticated OS Command Injection to Host Compromise (CVE-2026-58455) Dockwatch's loader.php issues an authentication redirect but forgets to call exit() afterward (Execution After Redirect), so code keeps running past the auth check. Combined with unsanitized input reaching shell_exec() in ajax/compose.php, a remote unauthenticated attacker can seed the required session flag, then inject arbitrary shell commands via the composePath POST parameter in the composePull action. Since Dockwatch is typically deployed with the Docker socket mounted, command execution translates directly into full host compromise. The flaw needs no authentication and no user interaction. 👉Affected: Dockwatch ≤ 0.6.567 - apply the fix from PR #135 / update to the patched build.

    Post summary

    Dockwatch is vulnerable to an unauthenticated OS command injection (CVE‑2026‑58455) that can lead to host compromise; patching to the latest build or applying PR #135 is required.

    0000074
    236 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58455 Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploitin… https://www.cve.org/CVERecord?id=CVE-2026-58455 ----- Traducción: CVE-2026-58455 Doc… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑58455, noting a Dockwatch 0.6.567 unauthenticated OS command injection allowing arbitrary shell execution. No PoC, exploit, patch, or active exploitation details are included.

    0000032
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-58455 Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploitin… https://www.cve.org/CVERecord?id=CVE-2026-58455

    Post summary

    The passage identifies CVE‑2026‑58455 as an unauthenticated OS command injection in Dockwatch (≤ 0.6.567) that permits arbitrary shell command execution; no PoC, exploit code, or patch details are mentioned.

    00000738
    57.7K followersView on X

Explore more