๐Ÿ” CVE Alert

CVE-2026-106581

UNKNOWN 0.0

Docker Desktop for Windows installer failed to verify external packages

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convince a user to approve the Docker-signed UAC prompt could execute attacker-controlled installer actions as LocalSystem.

CWE CWE-347
Vendor docker
Product docker desktop
Ecosystems
Industries
Technology
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for docker docker desktop

Be the first to know when new unknown vulnerabilities affecting docker docker desktop are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Docker / Docker Desktop
0 < 4.92.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.docker.com: https://docs.docker.com/desktop/release-notes/#4920

Credits

Trung Nguyen (@everping) of CyStack