CVE-2026-5843 – Docker Desktop
“Weak controls inside developer infrastructure can quickly expose the systems used to build and deploy everything else.”
Docker released patches for three high-severity vulnerabilities affecting Docker Desktop. CVE-2026-6406 has a CVSS score of 8.8, which is High severity. CVE-2026-5843 has a CVSS score of 8.2, which is High severity. CVE-2026-5817 has a CVSS score of 8.2, which is High severity.
The vulnerabilities involve improper authorization handling and untrusted functionality inclusion risks within affected Docker Desktop environments. One issue could allow privilege escalation, while the others could expose systems to unsafe external resource handling. The updates strengthen authorization protections and reduce the risk of insecure component interaction across developer and container workflows.
Key Details
- Affected Product
- Docker Docker Desktop
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- Required
- CWE Classification
- CWE-829