
Fun story: a self-hosted #Docker container manager, official image,standard config, docker.sock mounted exactly like every setup guide tells you to. Preauth. RCE + confirmed container escape to host on default config... and still currently unpatched ! CVE-2026-58455 / CVSS 9.8. Two bugs chained as "#0day" exploit: 1 - loader.php keeps processing after an auth redirect, no exit() 2 - ajax/compose.php feeds composePath straight into shell_exec() RCE in the container -> straight out to the host through the socket the app needs to do its job 👌 "Container escapes are usually bad admin config", they say. W00T ? Here we have an official image, default docker-compose, zero tuning => Perfect counterexample ! So why this .gif clip ? 👉because this is genuinely that easy to reach+ it illustrates, one more time, why focusing on patch mgmt is a huge mistake in 2026 ! You said "0-day" exploit ? Yep: No fix merged yet; the researcher's own patch (PR #135) was closed by the maintainer, folded into unrelated upcoming changes, *no ETA given*. PoC and full chain withheld until an actual fix ships. Not every exploited bug is patchable on day one. > Assume breach is the mindset, not the panic button. No public exploit does not mean not exploitable 🔥 + Remember: #Docker != secure, even with a team actively maintaining the product. Advisory by @VulnCheckAI : https://www.vulncheck.com/advisories/dockwatch-unauthenticated-os-command-injection-via-ajax-compose-php Credit: rayyb0t (https://github.com/rayyb0t)
Post summary
The post announces an unpatched pre‑auth RCE in a Docker container manager (CVE‑2026‑58455) with detailed vulnerability description, but no PoC, exploit code, or active exploitation evidence is provided.









