CVE-2026-53988: Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints

Published Sep 29, 2026
·
Updated

Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts.

Affected Software

1 affected component
Dockhand Dockhand<1.0.40

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Dockhand to a version that resolves this vulnerability.

    Fixed in 1.0.40

Event History

Sep 29, 2026
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to unauthenticated triggering?

Dockhand deployments running a version earlier than 1.0.40 are exposed if their git webhook endpoints are reachable by a remote attacker. The affected endpoints allow unsigned webhook requests because of a null webhook-secret guard condition.

2

What does an attacker need to escalate beyond redeployment-based denial of service?

An attacker needs write access to the git branch tracked by a target stack. They can then combine an unsigned webhook trigger with an attacker-controlled docker-compose.yml, potentially using privileged bind mounts to escape containers and compromise the host.

3

How can an attacker identify target stacks?

The stack IDs can be enumerated because they are sequential. An attacker can use those IDs when sending unsigned requests to trigger git clone and Docker Compose operations for target stacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203