Package Installation Vulnerability in Docker Desktop for Windows
CVE-2026-106581

8.2HIGH

Key Information:

Vendor

Docker

Vendor
CVE Published:
9 October 2026

What is CVE-2026-106581?

A security issue exists in Docker Desktop for Windows prior to version 4.92.0, where the application fails to verify the signature of a supplied package during installation. This vulnerability allows an attacker to present a malicious package and, if successfully convincing the user to approve the Docker-signed User Account Control (UAC) prompt, execute harmful installer actions with LocalSystem privileges. This significant flaw could compromise the system's integrity and expose it to further attacks.

Affected Version(s)

Docker Desktop Windows 0 < 4.92.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trung Nguyen (@everping) of CyStack
.