CVE-2026-66384

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

  • Published Aug 12, 2026
  • CVSS 5.3 medium
  • 0.7% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

CVE-2026-66384 at the National Vulnerability Database