No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 12 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only. | |
| Title | Docker Sandboxes read-only runtime mount writable through its shared-export alias | |
| First Time appeared |
Docker
Docker docker Sandboxes |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Docker
Docker docker Sandboxes |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-08-12T17:02:13.455Z
Reserved: 2026-07-28T21:28:23.642Z
Link: CVE-2026-18171
Updated: 2026-08-12T17:02:04.406Z
Status : Received
Published: 2026-08-12T15:17:32.477
Modified: 2026-08-12T18:17:27.893
Link: CVE-2026-18171
No data.
OpenCVE Enrichment
No data.