Imperva disclosed CopyEscape, tracked as CVE-2026-17106, a container-to-host arbitrary file-write vulnerability in Docker’s docker cp functionality that allows a malicious container to create or overwrite files outside the destination chosen by the user on the machine running the Docker CLI. The issue stems from a filesystem race in Docker’s archive creation path combined with unsafe symlink handling during extraction, turning a routine file copy from a container into a host write primitive.
Docker confirmed the same CVE also affects sbx cp in Docker Sandboxes when copying files out of sandboxes. Imperva said exploitation was validated against Docker Engine 29.6.1 on Linux and Docker Desktop 4.81.0 on macOS, with impact ranging from compromise of the developer account using the CLI to root code execution when docker cp is run with elevated privileges. Fixes are available in Docker Engine and CLI 29.7.2 or later, Docker Desktop 4.86.0 or later, and Docker Sandboxes 0.38.0 or later.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Docker released Docker Desktop 4.86.0 with Docker Engine 29.7.2 to address CVE-2026-17106. These versions were identified as the fixed releases for the vulnerable `docker cp` behavior.
Docker Sandboxes 0.38.0 shipped a fix for the related destination-escape flaw in `sbx cp` copy-out under CVE-2026-17106. Docker had confirmed the same CVE also affected copying files out of Docker Sandboxes.
On July 14, 2026, Docker said it was pursuing two remediation tracks for CVE-2026-17106: hardening the extraction library as the primary fix and hardening the source filesystem walk as defense in depth. The reference also notes follow-up fixes were needed after initial hardening caused significant functional regressions.
Imperva reported the container-to-host arbitrary file-write vulnerability CVE-2026-17106 in Docker's `docker cp` functionality to Docker. The flaw could let a malicious container overwrite files outside the user-selected destination on the machine running the Docker CLI.
A public proof-of-concept exploit became available for CVE-2026-17106, increasing the risk of exploitation of the Docker `docker cp`/`sbx cp` flaw. The reference notes Docker had already patched the issue and recommends updating Docker Desktop to 4.86.0 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcethecybersecguru.com
Open sourcereddit.com
Open sourceimperva.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.