CVE-2026-6406Disclosure(apple / docker_desktop)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. However, the --use-api-socket flag adds the Docker socket mount via the HostConfig.Mounts field rather than the HostConfig.Binds field. The ECI enforcement in the Docker Desktop API proxy only inspected Binds, allowing the mount to pass unchecked. This grants a container full access to the Docker Engine socket and, if the host user has logged in to container registries, their authentication credentials. A local attacker with the ability to run Docker CLI commands can exploit this to escape ECI restrictions, access the Docker Engine, and potentially escalate privileges.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • docker_desktop
  • linux_kernel
  • macos
  • windows

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-23)
  • 4 total mentions across 3 days

Affected systems

Products
docker_desktoplinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-24: 1Mentions · 2026-04-26: 1Mentions · 2026-05-23: 2Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 1Technical Details · 2026-05-23: 204-2404-2605-23
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-261
Disclosure1
2026-05-232
Disclosure2
Full discourse4 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-299|CVE-2026-6406] Docker Desktop Enhanced Container Isolation Exposed Dangerous Function Local Privilege Escalation Vulnerability (CVSS 8.8; Credit: Nitesh Surana (http://niteshsurana.com) of Trend Research) https://www.zerodayinitiative.com/advisories/ZDI-26-299/

    Post summary

    The advisory announces CVE‑2026‑6406, a Local Privilege Escalation flaw in Docker Desktop’s Enhanced Container Isolation, rated CVSS 8.8.

    01041831
    5.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6406 The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containe… https://www.cve.org/CVERecord?id=CVE-2026-6406 ----- Traducción: CVE-2026-6406 La … http://infoflow.cloud`

    Post summary

    The tweet discloses CVE-2026-6406, describing how the Docker CLI flag bypasses ECI restrictions, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000048
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6406 The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containe… https://www.cve.org/CVERecord?id=CVE-2026-6406

    Post summary

    CVE‑2026‑6406 is disclosed as a Docker Desktop flaw where the '--use-api-socket' flag bypasses Enhanced Container Isolation, allowing Docker socket mounts when ECI is enabled.

    00000309
    57.5K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Docker Desktop Enhanced Container Isolation Exposed Dangerous Function Local Privilege Escalation Vulnerability (CVE-2026-6406) #CVE20266406 #CyberSecurity #Docker #LocalPrivilegeEscalation https://www.systemtek.co.uk/?p=50814 https://t.co/oVQxeOPEpd

    Post summary

    The post announces a local privilege escalation vulnerability (CVE‑2026‑6406) affecting Docker Desktop’s enhanced container isolation.

    0000038
    1.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appdockerdocker_desktop---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more