logo

Docker Authorization Bypass Flaw Exposed Hosts to Potential Attackers

ID: 65619d7b-6fba-5c7e-8d8c-3554acba77f4

STIX ID: report--65619d7b-6fba-5c7e-8d8c-3554acba77f4

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Divya

...
...

A high-severity authorization bypass in Docker Engine (CVE-2026-34040) lets local, low-privileged attackers send crafted API requests that strip the request body before AuthZ plugin evaluation, enabling actions the plugin would otherwise block; it affects Docker Engine versions prior to 29.3.1 when AuthZ plugins are used. Administrators should upgrade to 29.3.1 immediately; if patching is not possible, mitigate by restricting Docker API access and avoiding AuthZ plugins that depend on request-body inspection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.