CVE-2026-66384: Authenticated users may write data outside the intended Docker cache path
Published Aug 12, 2026
·Updated
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Affected Software
1 affected component
Docker
Event History
Aug 12, 2026
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66384?
The severity of CVE-2026-66384 is medium, rated at 5.3.
2
What type of vulnerability is CVE-2026-66384?
CVE-2026-66384 is classified as a Path Traversal vulnerability.
3
How does CVE-2026-66384 affect Docker?
CVE-2026-66384 allows authenticated users to write data outside the intended Docker cache path.
4
Who is affected by CVE-2026-66384?
Authenticated users with specific remote-repository conditions are affected by CVE-2026-66384.
5
How can I mitigate the risks associated with CVE-2026-66384?
To mitigate CVE-2026-66384, restrict user permissions and validate input paths in Docker configurations.