CVE-2026-106581 PUBLISHED

Docker Desktop for Windows installer failed to verify external packages

Assigner: Docker
Reserved: 06.10.2026 Published: 09.10.2026 Updated: 09.10.2026

Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convince a user to approve the Docker-signed UAC prompt could execute attacker-controlled installer actions as LocalSystem.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 8.2

Product Status

Vendor Docker
Product Docker Desktop
Versions Default: unaffected
  • affected from 0 to 4.92.0 (excl.)

Workarounds

Do not run Docker Desktop Installer.exe with untrusted -package files.

Credits

  • Trung Nguyen (@everping) of CyStack finder

References

Problem Types

  • CWE-347: Improper Verification of Cryptographic Signature CWE