MEDIUM🇵🇱 Wersja polska

CVE-2026-33997

CVSS 6.8v3.1pub. 2026-03-31upd. 2026-08-24

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
  • Docker Engine

    APP
    Docker
    < 29.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2026-42306HIGH7.2same product

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 2...

CVE-2026-34040HIGH8.8same product

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detecte...

CVE-2026-41568MEDIUM6.1same product

Moby to otwarty framework kontenerowy. W Docker Engine przed wersją 29.5.1, Docker Daemon w wersji 28.5.2 i wc...

CVE-2020-13401MEDIUM6.0same product

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW cap...

CVE-2018-20699MEDIUM4.9same product

Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a la...