An unsigned webhook request is enough to trigger a stack redeployment on Dockhand versions before 1.0.40.
CVE-2026-53988 is rated CVSS 10.0. The git webhook endpoints skip authentication entirely when the webhook secret is null — the default configuration. Any unauthenticated attacker who can reach the endpoint and enumerate a stack ID can force arbitrary redeployments.
Immediate impact: denial of service via repeated forced redeployments.
Worst case: if the attacker also has write access to the tracked git branch, they can push a malicious docker-compose.yml with privileged bind mounts, escape the container, and compromise the underlying host.
Fix: Upgrade to Dockhand 1.0.40. Set a strong webhook secret. Restrict network access to webhook endpoints.
Full technical breakdown → https://threataft.com/articles/dockhand-cve-2026-53988-unauthenticated-webhook-authentication-bypass
Top comments (0)