PT-2026-28593 · Docker+1 · Docker+1

Manizada

·

Published

2026-03-25

·

Updated

2026-05-24

·

CVE-2026-34040

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moby/Docker Engine versions prior to 29.3.1
Description A security flaw in the Moby/Docker Engine allows attackers with local access to the Docker API or container to bypass authorization plugins (AuthZ). By using specially crafted, oversized HTTP request bodies, an attacker can cause the Docker daemon to forward requests to an authorization plugin without the body. This enables the evasion of access control decisions that rely on request body inspection, potentially allowing unauthorized daemon and container operations. This can lead to the creation of privileged containers with full host filesystem access, resulting in container escape, privilege escalation to the host, and complete host compromise.
Recommendations Upgrade Moby/Docker Engine to version 29.3.1 or later. Restrict Docker API access using TLS, firewall rules, and socket permissions to limit access to trusted users and networks. Avoid using AuthZ plugins that rely on request body inspection for security decisions as a temporary workaround. Review and harden AuthZ plugin configurations and validate request handling. Monitor Docker daemon and API logs for anomalous or crafted requests. Run Docker in rootless mode to mitigate risks. Remove or restrict untrusted authorization plugins.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BU65096
CLEANSTART-2026-ET12387
CLEANSTART-2026-FK40318
CLEANSTART-2026-FV86809
CLEANSTART-2026-GN78570
CLEANSTART-2026-JG72006
CLEANSTART-2026-NB83265
CLEANSTART-2026-NR54556
CLEANSTART-2026-QV77143
CLEANSTART-2026-QW08095
CLEANSTART-2026-TH33219
CLEANSTART-2026-VT65447
CVE-2026-34040
ECHO-65C5-C654-E8D5
GHSA-X744-4WPC-V9H2
GO-2026-4887
OESA-2026-1888
OESA-2026-2138
SUSE-SU-2026:1205-1

Affected Products

Docker
Red Os