Vendor
Remote attackers can exploit an unauthenticated OS command injection vulnerability (CVE-2026-58455) in Dockwatch versions up to 0.6.567, arising from a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php, to execute arbitrary shell commands leading to full host compromise, especially in deployments where the Docker socket is mounted.