A vulnerability labeled as critical has been found in Docker model-runner up to 1.0.15. Impacted is an unknown function of the file /engines/_configure of the component API. Executing a manipulation can lead to exposed dangerous routine.
This vulnerability is tracked as CVE-2026-28400. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.