CVE-2026-82430: Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the ent
Summary
CVE-2026-82430 is a privilege escalation vulnerability in Docker and OCI worker launchers where an attacker can modify a command file between when the system changes file ownership and when it reads that file, allowing them to execute arbitrary commands with root privileges and access the host filesystem.
Solution / Mitigation
Upgrade to version 3.1.0, where the command file is validated before the ownership change and re-verified on open, and where mount sources and destinations are constrained by configuration. The launcher must be rebuilt and reinstalled after upgrading. As a temporary workaround, disable Docker and OCI worker isolation or restrict topology submission on affected supervisors to trusted principals only.
Vulnerability Details
EPSS: 0.0%
September 14, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82430
First tracked: September 14, 2026 at 02:11 PM
Classified by LLM (prompt v3) · confidence: 95%