CVE-2026-34040
Aliases:GHSA-x744-4wpc-v9h2GO-2026-4887
Advisory lineage Upstream: 0 Downstream: 7
Analyzed
Published: 31 Mar 2026, 01:36
Last modified:02 Apr 2026, 03:55
Vulnerability Summary
Overall Risk (default)
medium
37/100 CVSS Score
8.8 HIGH
v3.1 (cve.org)
EPSS Score
8.12% LOW
8% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
31 Mar 2026, 01:36
Published
Vulnerability first disclosed
02 Apr 2026, 03:55
Last Modified
Vulnerability information updated
Description
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
CVSS Metrics
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 8.12%• Percentile: 94%
Techniques & Countermeasures
- CWE-288•Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Affected Systems
- docker•engine
< 29.3.1
- github.com/docker•docker
all | < 29.3.1
- github.com/moby•moby
all | < 29.3.1
- github.com/moby/moby•v2
< 2.0.0-beta.8
- moby•moby
< 29.3.1
- mobyproject•moby
< 29.3.1
References (7)
- https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq
- https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2
- https://github.com/moby/moby/commit/e89edb19ad7de0407a5d31e3111cb01aa10b5a38
- https://docs.docker.com/engine/extend/plugins_authorization
- https://github.com/moby/moby
- https://github.com/moby/moby/releases/tag/docker-v29.3.1
- https://nvd.nist.gov/vuln/detail/CVE-2026-34040