CVE-2026-15788: WCOW cache mount source selector resolves NTFS junctions outside of cache root
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not allow untrusted users to author builds that run on a WCOW-configured BuildKit daemon; ensure only trusted build authors can submit builds to that BuildKit daemon.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15788?
CVE-2026-15788 has a medium severity score of 5.6.
How do I fix CVE-2026-15788?
To mitigate CVE-2026-15788, ensure that you validate all input sources before sharing them in your Docker BuildKit environment.
What software is affected by CVE-2026-15788?
CVE-2026-15788 affects Docker BuildKit running on Windows Container on Windows (WCOW) workers.
What does CVE-2026-15788 vulnerability exploit?
CVE-2026-15788 allows unauthorized access to arbitrary host files through NTFS junctions in the cache mount source selector.
When was CVE-2026-15788 published?
CVE-2026-15788 was published on July 20, 2026.