EIP-2026-102823

PRE-CVE

Docker Daemon - Unprotected TCP Socket

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102823. PoCs published by Martin Pizala.

AI-analyzed exploit summary This exploit leverages an unprotected Docker TCP socket to create a container with the host's root filesystem mounted, allowing an attacker to escape the container and gain shell access on the host via chroot.

Description

Docker Daemon - Unprotected TCP Socket

Exploits (1)

exploitdb WORKING POC
by Martin Pizala · textlocallinux
https://www.exploit-db.com/exploits/42356

This exploit leverages an unprotected Docker TCP socket to create a container with the host's root filesystem mounted, allowing an attacker to escape the container and gain shell access on the host via chroot.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Docker Daemon (since 0.4.7, tested on Docker CE 17.06.0-ce and Docker Engine 1.13.1)
No auth needed
Prerequisites: Docker daemon with unprotected TCP socket (2375/tcp or 2376/tcp without TLS authentication)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026