CVE-2025-15558HIGH 8.0EPSS p34.2%

CVE-2025-15558CVE-2025-15558

Description

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user. This issue affects Docker CLI: through 29.1.5 and Windows binaries acting as a CLI-plugin manager using the github.com/docker/cli/cli-plugins/manager https://pkg.go.dev/github.com/docker/cli@v29.1.5+incompatible/cli-plugins/manager  package, such as Docker Compose. This issue does not impact non-Windows binaries, and projects not using the plugin-manager code.

Scoring

CVSS 3.18.0 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS0.43% probability of exploitation · percentile 34.2% · 2026-06-19T12:03:05Z
Published2026-03-04
Last modified2026-03-09

Underlying weaknesses· 1

CWE-427

References

  1. https://docs.docker.com/desktop/release-notes/
  2. https://github.com/docker/cli/pull/6713
  3. https://www.zerodayinitiative.com/advisories/ZDI-CAN-28304/

1

TypeTargetConfidenceTier
WeaknessUncontrolled Search Path Elementcwe-4270%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Docker Desktop Community Edition Privilege Escalation Vulnerability
CVE
CVE-2026-44848
CVE
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
CVE
CVE-2025-54531
CVE
CVE-2026-6406
CVE
CVE-2025-59291
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.