Vulnerability Description
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mobyproject | Moby | < 29.3.1 |
Related Weaknesses (CWE)
References
- https://github.com/moby/moby/releases/tag/docker-v29.3.1Release Notes
- https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2Vendor Advisory
FAQ
What is CVE-2026-34040?
CVE-2026-34040 is a vulnerability with a CVSS score of 8.8 (HIGH). Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patch...
How severe is CVE-2026-34040?
CVE-2026-34040 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-34040?
Check the references section above for vendor advisories and patch information. Affected products include: Mobyproject Moby.