CVE-2026-58455: Execution After Redirect (EAR) in Notifiarr dockwatch
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php. Attackers can seed the required session flag through the incomplete auth check, then inject arbitrary commands via the composePath POST parameter in the composePull action to achieve full host compromise, facilitated by the standard deployment mounting of the Docker socket.
AI Analysis
Technical Summary
CVE-2026-58455 is an unauthenticated OS command injection vulnerability in Notifiarr dockwatch up to version 0.6.567. The issue arises from a missing exit() call after an authentication redirect in loader.php, which allows attackers to bypass authentication checks. Combined with unsanitized input passed to shell_exec() in ajax/compose.php, attackers can inject arbitrary shell commands via the composePath POST parameter in the composePull action. This vulnerability enables remote attackers to achieve full host compromise, facilitated by the standard deployment mounting of the Docker socket.
Potential Impact
The vulnerability allows remote unauthenticated attackers to execute arbitrary shell commands on the host running dockwatch. This can lead to full host compromise, including potential control over Docker containers and the underlying system due to the Docker socket being mounted by default. The CVSS 4.0 score is 9.2, indicating critical severity with high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the dockwatch service to trusted networks only and avoid exposing it publicly. Monitor for updates from Notifiarr regarding patches or official mitigations.
CVE-2026-58455: Execution After Redirect (EAR) in Notifiarr dockwatch
Description
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php. Attackers can seed the required session flag through the incomplete auth check, then inject arbitrary commands via the composePath POST parameter in the composePull action to achieve full host compromise, facilitated by the standard deployment mounting of the Docker socket.
CVSS v4.0
Score 9.2critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-58455 is an unauthenticated OS command injection vulnerability in Notifiarr dockwatch up to version 0.6.567. The issue arises from a missing exit() call after an authentication redirect in loader.php, which allows attackers to bypass authentication checks. Combined with unsanitized input passed to shell_exec() in ajax/compose.php, attackers can inject arbitrary shell commands via the composePath POST parameter in the composePull action. This vulnerability enables remote attackers to achieve full host compromise, facilitated by the standard deployment mounting of the Docker socket.
Potential Impact
The vulnerability allows remote unauthenticated attackers to execute arbitrary shell commands on the host running dockwatch. This can lead to full host compromise, including potential control over Docker containers and the underlying system due to the Docker socket being mounted by default. The CVSS 4.0 score is 9.2, indicating critical severity with high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the dockwatch service to trusted networks only and avoid exposing it publicly. Monitor for updates from Notifiarr regarding patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-06-30T20:20:33.789Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a468c9f27e9c79719a1ceec
Added to database: 07/02/2026, 16:06:55 UTC
Last enriched: 07/17/2026, 09:06:41 UTC
Last updated: 08/15/2026, 12:41:10 UTC
Views: 121
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.