PatchSiren cyber security CVE debrief
CVE-2026-73040 louislam CVE debrief
CVE-2026-73040 Dockge Path Traversal via Unvalidated Stack Name Allows Arbitrary Compose and .env Disclosure and Arbitrary Directory Deletion. The vulnerability is caused by an unvalidated stack name in the Dockge application, allowing authenticated users to disclose sensitive information and delete arbitrary directories. This issue can be exploited without additional authentication when disableAuth is configured. The vulnerability has a high severity score and can be mitigated by reviewing and validating the application configuration, implementing additional authentication and authorization checks, and monitoring the application for suspicious activity.
- Vendor
- louislam
- Product
- dockge
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-20
- Original CVE updated
- 2026-09-23
- Advisory published
- 2026-08-20
- Advisory updated
- 2026-09-23
Who should care
Administrators and users of the Dockge application should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and validating the application configuration, implementing additional authentication and authorization checks, and monitoring the application for suspicious activity.
Why it matters
CVE-2026-73040 is a high-severity vulnerability in the Dockge application that allows authenticated users to disclose sensitive information and delete arbitrary directories. The vulnerability is caused by a path traversal issue and can be exploited without additional authentication when disableAuth is configured. Administrators and users of the Dockge application should be aware of this vulnerability and take steps to mitigate it.
- Authenticated users can disclose sensitive information in .env or Compose files.
- Authenticated users can delete arbitrary directories.
- The vulnerability can be exploited without additional authentication when disableAuth is configured.
- The reachable set includes unrelated applications on the host when Dockge runs as root with access to the Docker socket.
Technical summary
The Dockge application is vulnerable to a path traversal attack due to an unvalidated stack name. An authenticated user can read the composeENV and composeYAML values of any directory the server process can reach, disclosing secrets in that directory's .env or Compose file, and can invoke delete(), removing that directory. The vulnerability can be exploited without additional authentication when disableAuth is configured. The reachable set includes unrelated applications on the host when Dockge runs as root with access to the Docker socket.
Defensive priority
High
Recommended defensive actions
- Review and validate the Dockge application configuration to ensure that it is properly secured.
- Implement additional authentication and authorization checks to prevent unauthorized access to sensitive directories and files.
- Monitor the Dockge application for suspicious activity and implement logging and auditing to detect potential security incidents.
- Apply patches or updates provided by the vendor to fix the vulnerability.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, which is caused by a path traversal issue in the Dockge application. An authenticated user can read the composeENV and composeYAML values of any directory the server process can reach, disclosing secrets in that directory's .env or Compose file, and can invoke delete(), removing that directory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73040 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73040
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73040 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73040
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/louislam/dockge
-
Source reference
Unverified legacy reference
URL: https://github.com/louislam/dockge/blob/1.5.0/backend/agent-socket-handlers/docker-socket-handler.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/louislam/dockge/blob/1.5.0/backend/stack.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/louislam/dockge/issues/994
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/dockge-path-traversal-via-unvalidated-stack-name-allows-arbitrary-compose-and-env-disclosure-and-arbitrary-directory-deletion
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.