PT-2026-28590 · Docker+1 · Docker+1

Cody

·

Published

2026-03-25

·

Updated

2026-05-24

·

CVE-2026-33997

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Docker (affected versions not specified)
Description A flaw exists in the Docker daemon’s privilege validation process during docker plugin install. The daemon does not fully enforce plugin privilege checks, potentially allowing unintended privilege escalation. This occurs because the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins requesting exactly one privilege are also affected, as no comparison is performed. Exploitation requires installing a plugin from a malicious source. The API endpoint involved is docker plugin install. The vulnerable parameter is the plugin configuration.
Recommendations Do not install plugins from untrusted sources. Carefully review all privileges requested during docker plugin install. Restrict access to the Docker daemon to trusted parties, following the principle of least privilege. Avoid relying on plugin privilege approval as the only control boundary for sensitive environments.

Exploit

Fix

LPE

DoS

Weakness Enumeration

Related Identifiers

CVE-2026-33997
ECHO-91B4-E7D6-F02C
GHSA-PXQ6-2PRW-CHJ9
GO-2026-4883
OESA-2026-2138
SUSE-SU-2026:1205-1

Affected Products

Docker
Red Os