CVE-2026-106581
Docker Desktop for Windows installer failed to verify external packages
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convince a user to approve the Docker-signed UAC prompt could execute attacker-controlled installer actions as LocalSystem.
| CWE | CWE-347 |
| Vendor | docker |
| Product | docker desktop |
| Ecosystems | |
| Industries | Technology |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for docker docker desktop
Be the first to know when new unknown vulnerabilities affecting docker docker desktop are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Docker / Docker Desktop
0 < 4.92.0
References
Credits
Trung Nguyen (@everping) of CyStack