---
id: CVE-2026-106581
title: >-
  Before 4.92.0, Docker Desktop for Windows did not verify the signature of a
  package supplied to Docker Desktop Installer.exe install -package
summary: >-
  Before 4.92.0, Docker Desktop for Windows did not verify the signature of a
  package supplied to Docker Desktop Installer.exe install -package. An attacker
  able to provide a crafted package and convince a user to approve the
  Docker-signed…
severity: none
cwe:
  - CWE-347
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T17:16:45.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106581'
references:
  - url: 'https://docs.docker.com/desktop/release-notes/#4920'
    label: security@docker.com
tags:
  - nvd
ingestedAt: '2026-10-09T15:00:31.364Z'
---

## Overview

Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convince a user to approve the Docker-signed UAC prompt could execute attacker-controlled installer actions as LocalSystem.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
