CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-53988 — Dockhand before 1.0.40 contains an authentication bypass vulnerability in its gi...

·Source: NIST NVD

Updated:

Executive Summary

Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or,

Analysis

Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts. CVSS Score: 10. Published: 2026-09-29T20:17:20.403.

Indicators of Compromise (1)

CVE (1)
CVE-2026-53988
Source Attribution

Originally published by NIST NVD on Sep 29, 2026. Verified by: NIST.

Related Threats