CVE-2026-34040
CVE-2026-34040 is a high-severity vulnerability in Docker Engine with a CVSS 3.x base score of 8.8. Its EPSS exploit-prediction score of 10% places it in the 95th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-288.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- EPSS exploit prediction: 10% (95th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-17289
- Weakness: CWE-288
- Affected product: Docker Engine
- Published:
- Last modified:
Description
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
Frequently asked questions
- What is CVE-2026-34040?
- Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
- How severe is CVE-2026-34040?
- CVE-2026-34040 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-34040 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 10% (95th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-34040?
- CVE-2026-34040 affects Docker Engine. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-34040?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-34040 have an EU (EUVD) identifier?
- Yes. CVE-2026-34040 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-17289.
- When was CVE-2026-34040 published?
- CVE-2026-34040 was published on 2026-03-31 and last updated on 2026-06-17.
References
- https://github.com/moby/moby/releases/tag/docker-v29.3.1
- https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2
Affected products (1)
- cpe:2.3:a:docker:engine:*:*:*:*:*:*:*:*
More vulnerabilities in Docker Engine
- CVE-2026-42306 — High (CVSS 7.2): Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and…
- CVE-2026-33997 — Medium (CVSS 6.8): Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that…
- CVE-2026-41568 — Medium (CVSS 6.1): Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and…
- CVE-2020-13401 — Medium (CVSS 6.0): An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability,…
- CVE-2018-20699 — Medium (CVSS 4.9): Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large…
All CVEs affecting Docker Engine →
Other CWE-288 vulnerabilities
- CVE-2026-33591 — Critical (CVSS 10.0): A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security…
- CVE-2026-53622 — Critical (CVSS 10.0): Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's…
- CVE-2026-48491 — Critical (CVSS 10.0): Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in…
- CVE-2026-48020 — Critical (CVSS 10.0): Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity…
- CVE-2026-20079 — Critical (CVSS 10.0): A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an…
- CVE-2024-10081 — Critical (CVSS 10.0): CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.…