Cyber & AI intelligence
Wasteland.
Briefs indexed2938
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-53988 2026-09-29

Dockhand Webhook Authentication Bypass (CVE-2026-53988) Enables Unauthenticated Stack Redeployments

"A critical authentication bypass in Dockhand before 1.0.40 lets unauthenticated remote attackers trigger arbitrary stack redeployments through its git webhook endpoints. In some configurations, this can lead to full…"

A critical authentication bypass in Dockhand before 1.0.40 lets unauthenticated remote attackers trigger arbitrary stack redeployments through its git webhook endpoints. In some configurations, this can lead to full host compromise.

What Is It

CVE-2026-53988 is a missing-authentication flaw (CWE-306) in the git webhook endpoints of Dockhand, a Finsys project. The endpoints contain a guard condition that fails when the webhook secret is null. Because of this, the endpoints accept unsigned webhook requests. Stack IDs are sequential, so an attacker can enumerate them and send these requests to force git clone and docker compose operations on the target stacks. VulnCheck disclosed the issue, and NVD published it on 2026-09-29. The NVD record has the status "Received."

Why It Matters

VulnCheck scores this flaw CVSS 3.1 10.0 (CRITICAL) (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and CVSS 4.0 9.2 (CRITICAL). An attacker needs no privileges and no user interaction, and can reach the flaw over the network.

On its own, the bypass lets an attacker force repeated redeployments. Depending on the size of the stacks and how often the attacker sends requests, this can cause denial of service. The bigger risk comes when an attacker also has write access to the git branch that Dockhand tracks. They can then commit a malicious docker-compose.yml with privileged bind mounts. According to the description, that can lead to container escape and full host compromise, depending on how the host and container runtime are configured.

The supplied CISA KEV entry is empty, so the source data does not confirm active exploitation.

What's Vulnerable

The NVD record lists no CPEs.

Patch Status

Version 1.0.40 fixes the issue, and the release is published on the project's GitHub repository. Operators running Dockhand should upgrade to 1.0.40 or later. CISA has not issued any required action or remediation deadline, because the KEV entry is empty. Until they can patch, operators should review who has write access to the git branches their Dockhand stacks track, since that access is what can turn this flaw into host compromise.

Sources