CVE-2026-106581EPSS p0.1%
CVE-2026-106581CVE-2026-106581
Description
Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convince a user to approve the Docker-signed UAC prompt could execute attacker-controlled installer actions as LocalSystem.
Scoring
| EPSS | 0.07% probability of exploitation · percentile 0.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |