PT-2026-28590 · Docker+1 · Docker+1

·

CVE-2026-33997

·

Published

2026-03-25

·

Updated

2026-07-30

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Docker (affected versions not specified)
Description A flaw exists in the Docker daemon’s privilege validation process during docker plugin install. The daemon does not fully enforce plugin privilege checks, potentially allowing unintended privilege escalation. This occurs because the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins requesting exactly one privilege are also affected, as no comparison is performed. Exploitation requires installing a plugin from a malicious source. The API endpoint involved is docker plugin install. The vulnerable parameter is the plugin configuration.
Recommendations Do not install plugins from untrusted sources. Carefully review all privileges requested during docker plugin install. Restrict access to the Docker daemon to trusted parties, following the principle of least privilege. Avoid relying on plugin privilege approval as the only control boundary for sensitive environments.

Exploit

Fix

DoS

LPE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07864
CLEANSTART-2026-PD78752
CVE-2026-33997
ECHO-91B4-E7D6-F02C
GHSA-PXQ6-2PRW-CHJ9
GO-2026-4883
OESA-2026-2138
OPENSUSE-SU-2026:11075-1
OPENSUSE-SU-2026:21205-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1205-1
SUSE-SU-2026:2578-1
SUSE-SU-2026:2579-1

Affected Products

Docker
Red Os