CVE-2026-79994 HIGH

CVE-2026-79994: Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race

Vendor Docker
Product Docker Sandboxes
Weakness CWE-367
Published September 15, 2026
Last update September 16, 2026

CVSS base score

8.7/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

What the vulnerability does

01Description

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side capabilities provided by the targeted socket.

Key dates

02Disclosure timeline

September 15, 2026 CVE published
September 16, 2026 Record updated