CVE-2026-39386·Docker vulnerability
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session termination, etc.). This results in a complete compromise of the instance. The vulnerability has been patched in v3.0.11 and v3.1.2. If upgrading is not immediately possible, the following mitigations can reduce risk: Restrict access to trusted users only (avoid granting accounts to untrusted parties); ensure all user passwords are strong and only shared with trusted individuals; run the instance only when needed; avoid leaving it continuously exposed; place the instance behind authentication layers such as a reverse proxy with additional access controls; disable or restrict access to the /api/profile endpoint if feasible; and/or monitor for suspicious privilege changes or unexpected administrative actions. Note that these are temporary mitigations and do not fully eliminate the vulnerability. Upgrading is strongly recommended.
- Severity
- high
- Software
- Docker
- Fixed in
- 3.1.2
- Published
- 2026-04-21
Affected versions
From: 3.1.0
Until: 3.1.2
Fixed in: 3.1.2
How to fix this CVE
Upgrade Docker to version 3.1.2 or later to close a privilege escalation flaw that allows authenticated users to gain full administrative control over the Neko virtual browser instance. This vulnerability enables attackers to bypass access controls and manipulate member management, room settings, and session management. Immediate patching is critical, as any user with valid credentials can escalate to admin without additional permissions.
sudo dnf update docker-ceDefensia detects this vulnerability
WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block or restrict all unauthenticated requests to the `/api/profile` endpoint and enforce multi-factor authentication for all administrative API calls to Neko. Monitor for unexpected privilege escalation patterns such as rapid changes to user roles or administrative settings from non-privileged accounts.How to check if you are affected
- Run `docker --version` to check the currently installed Docker version; compare against v3.1.2
- Execute `docker ps -a | grep neko` to identify if the Neko container is running and note its image tag
- Check Docker logs with `docker logs <neko_container_id> | grep -i 'auth\|admin\|privilege'` to search for unauthorized privilege changes
- Verify the patched version by inspecting the container image with `docker inspect <neko_image> | grep -A 5 'Version'` or re-pull and redeploy the image tagged v3.1.2 or later
FAQ
What is CVE-2026-39386?
CVE-2026-39386 is a privilege escalation vulnerability in Neko (a self-hosted virtual browser running in Docker) that allows any authenticated user to immediately gain full administrative control of the instance, including member management and broadcast control.
Is CVE-2026-39386 being actively exploited?
No, CVE-2026-39386 is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploit code is currently available.
What versions of Docker are affected by CVE-2026-39386?
Neko versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 are affected. The vulnerability is patched in v3.0.11 and v3.1.2.
How do I check if my server is vulnerable to CVE-2026-39386?
Run `docker inspect <neko_container_id> --format='{{.Config.Image}}'` to retrieve the image name and tag, then verify if it is version 3.1.0 or 3.1.1 (vulnerable) or 3.1.2+ (patched).
Does Defensia detect CVE-2026-39386?
Yes — Defensia's CVE advisory scanner compares installed Docker and container image versions against the NVD database. If Neko is running on a monitored server, CVE-2026-39386 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-39386. Free for 1 server.
Get started free