Multiple Vulnerabilities in Docker Sandboxes
Multiple vulnerabilities, including CVE-2026-77179 and CVE-2026-79994, in Docker Sandboxes versions prior to 0.42.0 could allow remote code execution, data confidentiality breaches, and integrity loss.
CVE search metadata
CVE search record: CVE-2026-77179. KEV: no. Product: Docker Sandboxes (< 0.42.0). Brief: Multiple Vulnerabilities in Docker Sandboxes. Brief link: https://feed.craftedsignal.io/briefs/2026-09-docker-vulnerabilities/
CVE search record: CVE-2026-79994. KEV: no. Product: Docker Sandboxes (< 0.42.0). Brief: Multiple Vulnerabilities in Docker Sandboxes. Brief link: https://feed.craftedsignal.io/briefs/2026-09-docker-vulnerabilities/
The French National Cybersecurity Agency (ANSSI) has published an advisory regarding multiple vulnerabilities identified within Docker Sandboxes. These vulnerabilities, identified as CVE-2026-77179 and CVE-2026-79994, affect versions prior to 0.42.0. If successfully exploited, these flaws could allow a remote attacker to achieve arbitrary code execution on the host or target container, compromise the confidentiality of sensitive data, or impact the integrity of stored or processed information. Organizations utilizing Docker Sandboxes are advised to refer to the official vendor security bulletin to apply the necessary patches. Given the potential for remote code execution, timely patching is critical to mitigate the risk of unauthorized system access.
Impact
Successful exploitation of these vulnerabilities may result in full remote control over the affected containerized environment. This exposure risks the exfiltration of sensitive data, modification of application logic, and broader lateral movement within the host system. The scope of impact extends to any organization deploying Docker Sandboxes in versions earlier than 0.42.0.
Recommendation
- Upgrade Docker Sandboxes to version 0.42.0 or later immediately.
- Review the official vendor security announcement at https://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994 to verify all addressed security fixes.
- Identify and inventory all systems running Docker Sandboxes in the environment to ensure comprehensive patching.
Mitigations
Upgrade Docker Sandboxes to version 0.42.0 or later
CVE-2026-77179, CVE-2026-79994