CVE-2026-58455
published 2026-07-02CVE-2026-58455: Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by…
PriorityP186critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
4.86%
91.1th percentile
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php. Attackers can seed the required session flag through the incomplete auth check, then inject arbitrary commands via the composePath POST parameter in the composePull action to achieve full host compromise, facilitated by the standard deployment mounting of the Docker socket.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| notifiarr | dockwatch | <= 0.6.567 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Notifiarr dockwatch up to 0.6.567 POST Parameter loader.php exit composePath redirect
vuldb·2026-07-02·CVSS 9.8
CVE-2026-58455 [CRITICAL] Notifiarr dockwatch up to 0.6.567 POST Parameter loader.php exit composePath redirect
A vulnerability described as critical has been identified in Notifiarr dockwatch up to 0.6.567. Affected is the function exit of the file loader.php of the component POST Parameter Handler. Such manipulation of the argument composePath leads to execution after redirect.
This vulnerability is listed as CVE-2026-58455. The attack may be performed from remote. There is no available exploit.
Applying a patch is advised to resolve this issue.
GHSA
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authen
ghsa_unreviewed·2026-07-02
CVE-2026-58455 [CRITICAL] CWE-78 Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authen
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php. Attackers can seed the required session flag through the incomplete auth check, then inject arbitrary commands via the composePath POST parameter in the composePull action to achieve full host compromise, facilitated by the standard deployment mounting of the Docker socket.
VulnCheck
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2026·CVSS 9.8
CVE-2026-58455 [CRITICAL] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php. Attackers can seed the required session flag through the incomplete auth check, then inject arbitrary commands via the composePath POST parameter in the composePull action to achieve full host compromise, facilitated by the standard deployment mounting of the Docker socket.
Affected: Notifiarr dockwatch
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use
No detection rules found.
Nuclei
Dockwatch <= 0.6.567 - OS Command Injection
nuclei·CVSS 9.8
CVE-2026-58455 [CRITICAL] Dockwatch <= 0.6.567 - OS Command Injection
Dockwatch <= 0.6.567 - OS Command Injection
Dockwatch through 0.6.567 contains an unauthenticated command injection caused by missing exit() after authentication redirect in loader.php and unsanitized input in ajax/compose.php, letting remote attackers execute arbitrary shell commands, exploit requires seeding a session flag via incomplete auth check.
Template:
id: CVE-2026-58455
info:
name: Dockwatch <= 0.6.567 - OS Command Injection
author: DhiyaneshDk
severity: critical
description: |
Dockwatch through 0.6.567 contains an unauthenticated command injection caused by missing exit() after authentication redirect in loader.php and unsanitized input in ajax/compose.php, letting remote attackers execute arbitrary shell commands, exploit requires seeding a session flag via incomplete auth
No writeups or analysis indexed.
2026-07-02
Published
Exploited in the wild