CVE-2026-15788 MEDIUM

CVE-2026-15788: WCOW cache mount source selector resolves NTFS junctions outside of cache root

Vendor Moby
Product BuildKit
Weakness CWE-59
Published July 20, 2026
Last update July 20, 2026

CVSS base score

5.6/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.

Key dates

02Disclosure timeline

July 20, 2026 CVE published