Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files
Docker CopyEscape (CVE-2026-17106) (TL-2026-2812), also tracked as CopyEscape, is a high-severity software vulnerability scored CVSS 7.1, first published 2026-09-30. It has no confirmed attribution, affects Docker Docker Engine / Docker CLI, references 1 CVE (CVE-2026-17106), maps to 7 MITRE ATT&CK techniques (T1059.004, T1204.003, T1543.001), and is covered by 9 detection rules and 8 indicators of compromise.
Key facts for TL-2026-2812
- Threat ID
- TL-2026-2812
- Also known as
- CopyEscape, GHSA-hfg8-hc9c-6c3h
- Severity
- HIGH
- CVSS
- 7.1 (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-09-30
- Last reviewed
- 2026-09-30
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, software development, cloud, devops
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
CVE-2026-17106 ("CopyEscape") chains a TOCTOU race in the Docker daemon's container-filesystem archiving with a symlink-confinement flaw in moby/go-archive tar extraction, so a malicious running container can make `docker cp` (or `sbx cp`) write files anywhere the invoking user can write on the host. Imperva's PoC replaced /usr/bin/runc for root code execution. Fixed in Docker Engine/CLI 29.7.2, Docker Desktop 4.86.0, Docker Sandboxes 0.38.0 and moby/go-archive 0.3.0.
How Docker CopyEscape (CVE-2026-17106) works
CopyEscape (CVE-2026-17106) was discovered by Ron Masas of Imperva's Red Team and reported to Docker on 2026-04-11. It chains two weaknesses in Docker's archive pipeline.
Producer side (daemon): when `docker cp` copies out of a running container, the daemon walks the container's live filesystem with filepath.WalkDir to build a tar stream. A process inside the container can race the walk, moving a directory aside and replacing it with a symlink between the traversal decision and the metadata (Lstat) call. Imperva's PoC used an LD_PRELOAD interposer to make a watched path appear as a regular file while presenting a directory to the daemon, and placed a large file before the pivot point, monitored via filesystem notifications, to signal when the walk reached the critical spot and widen the race window. The resulting tar holds two inconsistent entries: a symlink and a child entry that describes the directory it replaced.
Consumer side (CLI): the extractor in moby/go-archive validates a path built with filepath.Join using a lexical string-prefix check, but creates the symlink from the original hdr.Linkname value from the archive. The containment check therefore approves one path while the kernel follows another, and later entries are written through the symlink outside the user-specified destination. The same class of flaw was present in the Docker Sandboxes `sbx cp` copy-out path. The GitHub advisory GHSA-hfg8-hc9c-6c3h lists the affected go-archive helpers as Unpack, UnpackLayer, Untar, UntarUncompressed and ApplyLayer, and rates the issue CVSS v4.0 7.1 (High), CWE-22 and CWE-59. TOCTOU (CWE-367) describes the daemon-side race.
Impact is an arbitrary file create/overwrite primitive on the host, scoped to the privileges of the process running `docker cp`. On Linux, if `docker cp` is run with sudo or by root-privileged CI/automation, overwriting /usr/bin/runc (the container runtime binary) gives root code execution the next time Docker invokes it; Imperva's PoC replaced runc with a shell script. On macOS, the Docker CLI extracts archives coming from the Linux daemon VM, so a container can overwrite shell startup scripts, SSH configuration, LaunchAgents (persistence), source trees and cloud credentials. Exposed workflows include CI/CD artifact retrieval, developer log collection, incident-response evidence collection from suspected-compromised containers, and AI-agent workflows using Docker Sandboxes. User interaction is required: a user or automation must run `docker cp`/`sbx cp` against an attacker-controlled running container.
Disclosure timeline per Imperva: reported 2026-04-11, acknowledged 2026-04-14/15, CVE assigned 2026-07-24, moby/go-archive 0.3.0 and Engine/CLI 29.7.0 shipped the extraction fix 2026-07-30, functional regressions were reported 2026-07-31 leading to an extension, Docker Sandboxes 0.38.0 fixed `sbx cp` on 2026-08-06, and Docker Desktop 4.86.0 (bundling Engine 29.7.2) released and the issue was disclosed 2026-08-10. Public PoCs exist. No in-the-wild exploitation is reported and the CVE is not in CISA KEV (per Wiz). Sources disagree on the severity label: GBHackers calls it critical without a score, while the GHSA and Wiz rate it CVSS v4.0 7.1 High; this record uses the advisory score. Sources also differ on the first fixed Engine/CLI version (29.7.0 for the extraction fix; 29.7.2 is the final fixed release).
MITRE ATT&CK techniques used in TL-2026-2812
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1204.003 User Execution: Malicious Image
Persistence
T1543.001 Create or Modify System Process: Launch Agent; T1546.004 Event Triggered Execution: Unix Shell Configuration Modification; T1554 Compromise Host Software Binary
Defense Evasion
T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking
Privilege Escalation
Affected products and versions in Docker CopyEscape (CVE-2026-17106)
- Docker — Docker Engine / Docker CLI
Vulnerable versions: < 29.7.2 (29.6.1 and earlier confirmed by Imperva)
Fixed in: 29.7.2 - Docker — Docker Desktop
Vulnerable versions: < 4.86.0 (4.81.0 and earlier confirmed by Imperva)
Fixed in: 4.86.0 - Docker — Docker Sandboxes (sbx cp)
Vulnerable versions: < 0.38.0
Fixed in: 0.38.0 - Moby — moby/go-archive
Vulnerable versions: < 0.3.0
Fixed in: 0.3.0 - Docker — Docker Compose
Vulnerable versions: < 5.4.0
Fixed in: 5.4.0
Remediation for Docker CopyEscape (CVE-2026-17106)
Patches
- moby/go-archive 0.3.0 (GHSA-hfg8-hc9c-6c3h)
- Docker Engine/CLI 29.7.2
- Docker Desktop 4.86.0
- Docker Sandboxes 0.38.0
Immediate actions
- Upgrade Docker Engine/CLI to 29.7.2 or later, Docker Desktop to 4.86.0 or later, Docker Sandboxes to 0.38.0 or later
- Stop containers before copying files out (docker stop <container> && docker cp <container>:/path ./dest)
- Do not run docker cp / sbx cp against untrusted or suspected-compromised live containers
Workarounds
- Only extract trusted archives
- Stop the source container before docker cp so no live process can race the filesystem walk
Longer-term hardening
- Avoid running docker cp with sudo or from root-privileged CI/automation; use least-privilege accounts
- Collect artifacts from suspicious containers on isolated, disposable systems
- Treat archives and copy-out data from untrusted containers as hostile input
- Monitor integrity of /usr/bin/runc, shell startup files, SSH configuration and ~/Library/LaunchAgents
CVEs associated with Docker CopyEscape (CVE-2026-17106)
Weaknesses (CWE) in Docker CopyEscape (CVE-2026-17106)
CWE-22, CWE-59, CWE-367
Timeline of Docker CopyEscape (CVE-2026-17106)
- Imperva Red Team (Ron Masas) reports the docker cp flaw to Docker
- Docker acknowledges the report and confirms it as a valid finding (April 14-15)
- CVE-2026-17106 assigned; coordinated release initially targeted for August 3
- moby/go-archive 0.3.0 and Docker Engine/CLI 29.7.0 ship the extraction fix
- Functional regressions reported; extension of the disclosure date to August 10 requested
- Docker Sandboxes 0.38.0 fixes the sbx cp destination-escape flaw
- Docker Desktop 4.86.0 (bundling Engine 29.7.2) released; Imperva publishes CopyEscape research with PoC
- GHSA-hfg8-hc9c-6c3h / CVE-2026-17106 published with CVSS v4.0 7.1 (High)
- GBHackers reports CopyEscape and urges upgrade to 29.7.2 / 4.86.0 / 0.38.0
Sources cited for Docker CopyEscape (CVE-2026-17106)
- Docker CopyEscape CVE-2026-17106 Lets Malicious Containers Overwrite Host Files
- CopyEscape: Taking Over Docker Hosts with docker cp | Imperva
- GHSA-hfg8-hc9c-6c3h: moby/go-archive tar extraction fails to confine writes
- CVE-2026-17106 - Wiz Vulnerability Database
- CVE-2026-17106: moby/go-archive Symlink-Following Path Traversal in Tar Extraction
- CVE-2026-17106: Docker docker cp Container-to-Host Arbitrary File Write
More in vulnerability
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)
- Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution
Detection coverage for TL-2026-2812
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2812 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.