CVE-2025-9074: Docker Desktop allows unauthenticated access to Docker Engine API from containers

Published Aug 20, 2025
·
Updated

A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled, and with or without the "Expose daemon on tcp://localhost:2375 without TLS" option enabled. This can lead to execution of a wide range of privileged commands to the engine API, including controlling other containers, creating new ones, managing images etc. In some circumstances (e.g. Docker Desktop for Windows with WSL backend) it also allows mounting the host drive with the same privileges as the user running Docker Desktop.

Affected Software

1 affected component
Docker Docker Desktop

Event History

Aug 20, 2025
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Aug 25, 2025
News Published
via BleepingComputer·03:11 PM
News Published
via BleepingComputer·03:13 PM
Feb 4, 2026
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
03:50 PM

Frequently Asked Questions

1

What is the severity of CVE-2025-9074?

CVE-2025-9074 is considered a high severity vulnerability due to its potential to expose the Docker Engine API to unauthorized access.

2

How do I fix CVE-2025-9074?

To mitigate CVE-2025-9074, restrict access to the Docker Engine API by modifying your firewall rules or upgrading to the latest version of Docker Desktop that addresses this issue.

3

Which versions of Docker Desktop are affected by CVE-2025-9074?

CVE-2025-9074 affects multiple versions of Docker Desktop prior to the fix included in version 4.4.3.

4

Can CVE-2025-9074 be exploited without Enhanced Container Isolation?

Yes, CVE-2025-9074 can be exploited regardless of whether Enhanced Container Isolation is enabled or disabled.

5

What components of Docker are involved in CVE-2025-9074?

CVE-2025-9074 involves the Docker Engine API and the local network configuration allowing access through the predefined Docker subnet.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203