Cache Mount Issue in BuildKit on Windows Containers by Moby
CVE-2026-15788
5.6MEDIUM
What is CVE-2026-15788?
A flaw exists in BuildKit's cache mount functionality on Windows Container (WCOW) workers that fails to identify NTFS directory junctions within the cache root. This oversight allows a build initiated by an untrusted user on a WCOW-configured BuildKit daemon to potentially access sensitive host files that are otherwise restricted. This vulnerability raises significant concerns around the integrity and confidentiality of host systems operating in conjunction with BuildKit's caching mechanisms.
Affected Version(s)
BuildKit Windows 0 < 0.31.2
