Docker Vulnerability Let Attackers Bypass Authorization and Gain Host Access
ID: 9ebd9ecf-762b-5893-b6f1-6843742e3357
STIX ID: report--9ebd9ecf-762b-5893-b6f1-6843742e3357
Feed Name: cybersecurityNews.com
A high-severity Docker Engine vulnerability (CVE-2026-34040) allows attackers to bypass authorization plugins by crafting oversized API request bodies that are dropped before plugin inspection, potentially enabling low-privileged local actors to escape containers and compromise the host; Docker has released Engine 29.3.1 to address the flaw and recommends upgrading or applying mitigations such as avoiding body-dependent AuthZ plugins, restricting Docker API access, and enforcing least privilege.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
