Skip to content
0xcc.io·

🚨Omarchy Security Flaw Allows Root Access Without Password

Any user can now become root on Omarchy systems

TL;DR

Omarchy's default Docker configuration lets any user escalate to root without a password. The fix is in version 4.0.1, released on August 24, 2026. Developers should update immediately.

Omarchy's default Docker configuration now allows any user to escalate to root without a password, sudo, or a privilege prompt. This affects nearly every process where untrusted code could run, including AI coding agents, web browsers, editors, and background processes. The issue was introduced on June 1, 2025, and resolved on August 24, 2026, when the Docker group membership was removed from the default configuration. Developers must update to version 4.0.1 to prevent full machine compromise.

Key Points

1

Omarchy's default Docker configuration allows root access without a password, introduced June 1, 2025.

2

The issue was temporarily disabled on June 2, 2025, but re-enabled on June 17, 2025.

3

Version 4.0.1, released on August 24, 2026, resolves the security flaw.

4

Podman, a daemonless container runtime, does not require root access to run containers.

5

Developers should update their Omarchy systems to version 4.0.1 to secure their environments.

Why It Matters

If you're running untrusted code in Docker containers, your system is at risk. The default configuration in Omarchy versions prior to 4.0.1 allows any user to escalate to root. This affects nearly every process where untrusted code could run, including AI coding agents, web browsers, editors, and background processes. Update to 4.0.1 to prevent full machine compromise.

dockersecurityomarchyroot-accessupdate

Frequently Asked Questions

Why does this matter?

If you're running untrusted code in Docker containers, your system is at risk. The default configuration in Omarchy versions prior to 4.0.1 allows any user to escalate to root. This affects nearly every process where untrusted code could run, including AI coding agents, web browsers, editors, and background processes. Update to 4.0.1 to prevent full machine compromise.

What happened?

Omarchy's default Docker configuration lets any user escalate to root without a password. The fix is in version 4.0.1, released on August 24, 2026. Developers should update immediately.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,399 builders reading daily.

Also get