Permissions, Privileges, and Access Controls in Docker Desktop - CVE-2025-9074
Published: August 21, 2025 / Updated: January 9, 2026
Vulnerability details
The vulnerability allows a malicious container to execute arbitrary code on the system.
The vulnerability exists due to improperly imposed security restrictions. A malicious container can access the Docker Engine and launch additional containers without requiring the Docker socket to be mounted, leading to unauthorized access to files on the host system.
Affected software
How to mitigate CVE-2025-9074
Links to Public Exploits and PoC-codes
- Exploit #12270 - CVE-2025-9074-Docker-Exploit (January 9, 2026)
- Exploit #12208 - CVE-2025-9074 (A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system.) (December 17, 2025)
- Exploit #12009 - PoC-for-CVE-2025-9074 (October 8, 2025)
- Exploit #11929 - CVE-2025-9074 (September 5, 2025)
- Exploit #11892 - CVE-2025-9074 (August 29, 2025)