Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files

Docker CopyEscape (CVE-2026-17106) (TL-2026-2812), also tracked as CopyEscape, is a high-severity software vulnerability scored CVSS 7.1, first published 2026-09-30. It has no confirmed attribution, affects Docker Docker Engine / Docker CLI, references 1 CVE (CVE-2026-17106), maps to 7 MITRE ATT&CK techniques (T1059.004, T1204.003, T1543.001), and is covered by 9 detection rules and 8 indicators of compromise.

Key facts for TL-2026-2812

Threat ID
TL-2026-2812
Also known as
CopyEscape, GHSA-hfg8-hc9c-6c3h
Severity
HIGH
CVSS
7.1 (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
Status
PATCHED
Category
VULNERABILITY
First published
2026-09-30
Last reviewed
2026-09-30
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software development, cloud, devops
Target regions
Global
Detection rules
9
Indicators of compromise
8

CVE-2026-17106 ("CopyEscape") chains a TOCTOU race in the Docker daemon's container-filesystem archiving with a symlink-confinement flaw in moby/go-archive tar extraction, so a malicious running container can make `docker cp` (or `sbx cp`) write files anywhere the invoking user can write on the host. Imperva's PoC replaced /usr/bin/runc for root code execution. Fixed in Docker Engine/CLI 29.7.2, Docker Desktop 4.86.0, Docker Sandboxes 0.38.0 and moby/go-archive 0.3.0.

How Docker CopyEscape (CVE-2026-17106) works

CopyEscape (CVE-2026-17106) was discovered by Ron Masas of Imperva's Red Team and reported to Docker on 2026-04-11. It chains two weaknesses in Docker's archive pipeline.

Producer side (daemon): when `docker cp` copies out of a running container, the daemon walks the container's live filesystem with filepath.WalkDir to build a tar stream. A process inside the container can race the walk, moving a directory aside and replacing it with a symlink between the traversal decision and the metadata (Lstat) call. Imperva's PoC used an LD_PRELOAD interposer to make a watched path appear as a regular file while presenting a directory to the daemon, and placed a large file before the pivot point, monitored via filesystem notifications, to signal when the walk reached the critical spot and widen the race window. The resulting tar holds two inconsistent entries: a symlink and a child entry that describes the directory it replaced.

Consumer side (CLI): the extractor in moby/go-archive validates a path built with filepath.Join using a lexical string-prefix check, but creates the symlink from the original hdr.Linkname value from the archive. The containment check therefore approves one path while the kernel follows another, and later entries are written through the symlink outside the user-specified destination. The same class of flaw was present in the Docker Sandboxes `sbx cp` copy-out path. The GitHub advisory GHSA-hfg8-hc9c-6c3h lists the affected go-archive helpers as Unpack, UnpackLayer, Untar, UntarUncompressed and ApplyLayer, and rates the issue CVSS v4.0 7.1 (High), CWE-22 and CWE-59. TOCTOU (CWE-367) describes the daemon-side race.

Impact is an arbitrary file create/overwrite primitive on the host, scoped to the privileges of the process running `docker cp`. On Linux, if `docker cp` is run with sudo or by root-privileged CI/automation, overwriting /usr/bin/runc (the container runtime binary) gives root code execution the next time Docker invokes it; Imperva's PoC replaced runc with a shell script. On macOS, the Docker CLI extracts archives coming from the Linux daemon VM, so a container can overwrite shell startup scripts, SSH configuration, LaunchAgents (persistence), source trees and cloud credentials. Exposed workflows include CI/CD artifact retrieval, developer log collection, incident-response evidence collection from suspected-compromised containers, and AI-agent workflows using Docker Sandboxes. User interaction is required: a user or automation must run `docker cp`/`sbx cp` against an attacker-controlled running container.

Disclosure timeline per Imperva: reported 2026-04-11, acknowledged 2026-04-14/15, CVE assigned 2026-07-24, moby/go-archive 0.3.0 and Engine/CLI 29.7.0 shipped the extraction fix 2026-07-30, functional regressions were reported 2026-07-31 leading to an extension, Docker Sandboxes 0.38.0 fixed `sbx cp` on 2026-08-06, and Docker Desktop 4.86.0 (bundling Engine 29.7.2) released and the issue was disclosed 2026-08-10. Public PoCs exist. No in-the-wild exploitation is reported and the CVE is not in CISA KEV (per Wiz). Sources disagree on the severity label: GBHackers calls it critical without a score, while the GHSA and Wiz rate it CVSS v4.0 7.1 High; this record uses the advisory score. Sources also differ on the first fixed Engine/CLI version (29.7.0 for the extraction fix; 29.7.2 is the final fixed release).

MITRE ATT&CK techniques used in TL-2026-2812

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1204.003 User Execution: Malicious Image

Persistence

T1543.001 Create or Modify System Process: Launch Agent; T1546.004 Event Triggered Execution: Unix Shell Configuration Modification; T1554 Compromise Host Software Binary

Defense Evasion

T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking

Privilege Escalation

T1611 Escape to Host

Affected products and versions in Docker CopyEscape (CVE-2026-17106)

  • Docker — Docker Engine / Docker CLI
    Vulnerable versions: < 29.7.2 (29.6.1 and earlier confirmed by Imperva)
    Fixed in: 29.7.2
  • Docker — Docker Desktop
    Vulnerable versions: < 4.86.0 (4.81.0 and earlier confirmed by Imperva)
    Fixed in: 4.86.0
  • Docker — Docker Sandboxes (sbx cp)
    Vulnerable versions: < 0.38.0
    Fixed in: 0.38.0
  • Moby — moby/go-archive
    Vulnerable versions: < 0.3.0
    Fixed in: 0.3.0
  • Docker — Docker Compose
    Vulnerable versions: < 5.4.0
    Fixed in: 5.4.0

Remediation for Docker CopyEscape (CVE-2026-17106)

Patches

  • moby/go-archive 0.3.0 (GHSA-hfg8-hc9c-6c3h)
  • Docker Engine/CLI 29.7.2
  • Docker Desktop 4.86.0
  • Docker Sandboxes 0.38.0

Immediate actions

  • Upgrade Docker Engine/CLI to 29.7.2 or later, Docker Desktop to 4.86.0 or later, Docker Sandboxes to 0.38.0 or later
  • Stop containers before copying files out (docker stop <container> && docker cp <container>:/path ./dest)
  • Do not run docker cp / sbx cp against untrusted or suspected-compromised live containers

Workarounds

  • Only extract trusted archives
  • Stop the source container before docker cp so no live process can race the filesystem walk

Longer-term hardening

  • Avoid running docker cp with sudo or from root-privileged CI/automation; use least-privilege accounts
  • Collect artifacts from suspicious containers on isolated, disposable systems
  • Treat archives and copy-out data from untrusted containers as hostile input
  • Monitor integrity of /usr/bin/runc, shell startup files, SSH configuration and ~/Library/LaunchAgents

CVEs associated with Docker CopyEscape (CVE-2026-17106)

CVE-2026-17106

Weaknesses (CWE) in Docker CopyEscape (CVE-2026-17106)

CWE-22, CWE-59, CWE-367

Timeline of Docker CopyEscape (CVE-2026-17106)

  • Imperva Red Team (Ron Masas) reports the docker cp flaw to Docker
  • Docker acknowledges the report and confirms it as a valid finding (April 14-15)
  • CVE-2026-17106 assigned; coordinated release initially targeted for August 3
  • moby/go-archive 0.3.0 and Docker Engine/CLI 29.7.0 ship the extraction fix
  • Functional regressions reported; extension of the disclosure date to August 10 requested
  • Docker Sandboxes 0.38.0 fixes the sbx cp destination-escape flaw
  • Docker Desktop 4.86.0 (bundling Engine 29.7.2) released; Imperva publishes CopyEscape research with PoC
  • GHSA-hfg8-hc9c-6c3h / CVE-2026-17106 published with CVSS v4.0 7.1 (High)
  • GBHackers reports CopyEscape and urges upgrade to 29.7.2 / 4.86.0 / 0.38.0

Sources cited for Docker CopyEscape (CVE-2026-17106)

More in vulnerability

Detection coverage for TL-2026-2812

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2812 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats