Docker Authorization Bypass Flaw Exposed Hosts to Potential Attackers
ID: 65619d7b-6fba-5c7e-8d8c-3554acba77f4
STIX ID: report--65619d7b-6fba-5c7e-8d8c-3554acba77f4
Feed Name: GBHackers
A high-severity authorization bypass in Docker Engine (CVE-2026-34040) lets local, low-privileged attackers send crafted API requests that strip the request body before AuthZ plugin evaluation, enabling actions the plugin would otherwise block; it affects Docker Engine versions prior to 29.3.1 when AuthZ plugins are used. Administrators should upgrade to 29.3.1 immediately; if patching is not possible, mitigate by restricting Docker API access and avoiding AuthZ plugins that depend on request-body inspection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
