CVE-2026-53988
published 2026-09-29CVE-2026-53988: Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger…
PriorityP274critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.45%
37.2th percentile
Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| finsys | dockhand | < 1.0.40 | 1.0.40 |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Finsys Dockhand up to 1.0.39 Git Webhook Endpoint docker-compose.yml improper authentication
vuldb·2026-09-29·CVSS 10.0
CVE-2026-53988 [CRITICAL] Finsys Dockhand up to 1.0.39 Git Webhook Endpoint docker-compose.yml improper authentication
A vulnerability was found in Finsys Dockhand up to 1.0.39 and classified as very critical. This impacts an unknown function of the file docker-compose.yml of the component Git Webhook Endpoint. Executing a manipulation can lead to improper authentication.
This vulnerability is tracked as CVE-2026-53988. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting
ghsa_unreviewed·2026-09-29
CVE-2026-53988 [CRITICAL] CWE-306 Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting
Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-29
Published