chiprook
← Security
SecurityOctober 1, 2026, 12:37

Dockhand CVE-2026-53988: CVSS 10.0 unauthenticated webhook auth bypass

In Dockhand versions before 1.0.40, git webhook endpoints skip authentication entirely when the webhook secret is null, which is the default configuration. An unauthenticated attacker who can reach the endpoint and enumerate a stack ID can force arbitrary redeployments, and with write access to the tracked branch could push a malicious docker-compose.yml with privileged bind mounts to escape the container. Fix: upgrade to Dockhand 1.0.40 and set a strong webhook secret.

Dockhand CVE-2026-53988: CVSS 10.0 unauthenticated webhook auth bypass
#Dockhand
Read next
Security

Cisco FMC authentication bypass CVE-2026-20079 has CVSS 10.0

Security

Cisco warns of active exploitation of CVSS 9.8 SD-WAN Manager auth bypass

Security

CVE-2026-75650 in Magento: 132,792 Matches and a 10.0 CVSS

Security

CVSS 10.0 VeloCloud Orchestrator flaw actively exploited