Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-15789

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 5.9%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-15789


Contact Us

Shodan ® - All rights reserved