Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-79994
CVE
CVE-2026-79994
View on NVD ↗
Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race
MITRE ATT&CK TTPs
2
T1059
Command and Scripting Interpreter
Execution
T1222
File and Directory Permissions Modification
Defense Evasion
Source Articles
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
A critical vulnerability in Docker Sandboxes for macOS, tracked as CVE-2026-77179, allows malicious guest code running inside a virtual machine to escape the sandbox and read or modify arbitrary files on the host system by exploiting symlink handling in the virtio-fs host server. The flaw affects Docker Sandboxes versions 0.28.0 to 0.41.9 and was patched in version 0.42.0. A second high-severity issue, CVE-2026-79994, enables symlink-based path traversal to access Unix domain sockets outside the authorized workspace. No active exploitation has been reported, and both vulnerabilities were addressed in the same update.
hacker-news
Sep 17, 2026