CVE-2026-103433: CWE-862: Missing Authorization in Docker Docker Buildx
Description
CVE-2026-103433 is a medium severity vulnerability in Docker Buildx Bake where missing authorization checks allow untrusted Bake definitions to expose readable files or consume local OCI image layouts improperly. This occurs because the expected filesystem read approval is not requested for certain inputs, leading to potential unauthorized access to local files. The issue affects Docker Buildx versions from 0 up to but not including 0.37.2.
CVSS v4.0
Score 6.9medium
Affected software
Docker
Docker Buildx
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. This missing authorization (CWE-862) allows an untrusted Bake definition to expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname or to consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users running untrusted Bake definitions are affected. The vulnerability has a CVSS 4.0 score of 6.9 (medium severity) and affects versions >=0 <0.37.2.
Potential Impact
An attacker providing an untrusted Bake definition can gain unauthorized read access to local files or OCI image layouts outside the intended project scope. This could lead to exposure of sensitive information on the client side. There is no indication of privilege escalation or remote code execution. The vulnerability requires user interaction (UI:A) and no privileges (PR:N) but can result in high confidentiality impact (VC:H).
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid running untrusted Bake definitions or restrict Bake usage to trusted sources only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Docker
- Date Reserved
- 2026-09-30T15:33:07.765Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac41ec82cdf04f6564019f3
Added to database: 10/05/2026, 22:03:52 UTC
Last enriched: 10/05/2026, 22:18:22 UTC
Last updated: 10/05/2026, 22:19:02 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.