
Docker cp Vulnerability Allows Container-to-Host Arbitrary File Write (CVE-2026-17106)
dockervulnerabilityCVEcontainersecurityfilesystemrace_conditionsymlinkprivilege_escalation
A vulnerability in docker cp allows a malicious container to create or overwrite files on the host machine running the Docker CLI. The flaw exploits a filesystem race condition in Docker’s archive creation and unsafe symlink handling during extraction. It can lead to developer account compromise or root code execution, depending on the CLI user’s privileges. Docker confirmed that sbx cp (Docker Sandboxes) was also affected.