Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access
ID: 3bc0780b-cc91-5622-914c-76b6062551e6
STIX ID: report--3bc0780b-cc91-5622-914c-76b6062551e6
Feed Name: The Hacker News
**CVE-2026-34040 — Docker Engine authorization bypass (CVSS 8.8)**: A high-severity vulnerability in Docker Engine allows an attacker with Docker API access to craft a padded/oversized HTTP request that is dropped before reaching an AuthZ plugin, enabling the daemon to process the full request and create privileged containers with host filesystem access; this can lead to theft of cloud credentials, Kubernetes configs, SSH keys, and full host compromise. The issue stems from an incomplete fix for CVE-2024-41110, has been demonstrated in realistic scenarios (including automated AI agents that can construct the bypass), and is patched in Docker Engine 29.3.1; temporary mitigations include restricting Docker API access, avoiding AuthZ plugins that rely on request-body inspection, and running Docker rootless or with user namespace remapping.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
