logo

Docker Vulnerability Let Attackers Bypass Authorization and Gain Host Access

ID: 9ebd9ecf-762b-5893-b6f1-6843742e3357

STIX ID: report--9ebd9ecf-762b-5893-b6f1-6843742e3357

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-04-08

Date Updated: 2026-04-21

Author: Abinaya

...
...

A high-severity Docker Engine vulnerability (CVE-2026-34040) allows attackers to bypass authorization plugins by crafting oversized API request bodies that are dropped before plugin inspection, potentially enabling low-privileged local actors to escape containers and compromise the host; Docker has released Engine 29.3.1 to address the flaw and recommends upgrading or applying mitigations such as avoiding body-dependent AuthZ plugins, restricting Docker API access, and enforcing least privilege.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.