OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-53988

CRITICAL · CVSS 10 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Dockhand versions prior to 1.0.40 are vulnerable to an authentication bypass in their git webhook endpoints, allowing unauthenticated remote attackers to initiate arbitrary stack redeployments. This vulnerability can lead to denial of service or, if attackers have write access to the tracked git branch, potentially result in container escape and full host compromise through malicious docker-compose.yml files. Organizations using affected versions of Dockhand should prioritize immediate patching to mitigate these critical risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-53988
Severity
CRITICAL
CVSS
10
EPSS
0.45%
Docker

Original NVD Description

Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts.