{"id":"CVE-2026-34040","title":"Moby: Moby: Authorization bypass vulnerability (CVE-2026-34040)","summary":"A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container enviro…","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","cvssSource":"vendor","cwe":"CWE-807","vendor":"Red Hat","product":"Multicluster Global Hub 1.4.9","affected":["multicluster_engine_for_kubernetes","ceph_storage 5","openshift_container_platform 4","multicluster_global_hub 1.4.9","multicluster_global_hub 1.6.5","multicluster_global_hub 1.7.3","multicluster_global_hub 1.5.3"],"patched":["multicluster_global_hub 1.4.9","multicluster_global_hub 1.6.5","multicluster_global_hub 1.7.3","multicluster_global_hub 1.5.3"],"published":"2026-03-31","updated":"2026-09-21","sourceUpdated":"2026-09-21T11:29:30+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34040.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34040.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-34040"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2453278"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-34040"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34040"},{"url":"https://github.com/moby/moby/releases/tag/docker-v29.3.1"},{"url":"https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2"},{"url":"https://access.redhat.com/errata/RHSA-2026:22347"},{"url":"https://access.redhat.com/errata/RHSA-2026:67516"},{"url":"https://access.redhat.com/errata/RHSA-2026:23345"},{"url":"https://access.redhat.com/errata/RHSA-2026:24503"},{"url":"https://access.redhat.com/errata/RHSA-2026:67842"},{"url":"https://access.redhat.com/errata/RHSA-2026:21769"},{"url":"https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq"},{"url":"https://github.com/moby/moby/commit/e89edb19ad7de0407a5d31e3111cb01aa10b5a38"},{"url":"https://docs.docker.com/engine/extend/plugins_authorization"},{"url":"https://github.com/moby/moby"}],"tags":["csaf","vex","red-hat","exploit-available","osv","go"],"epss":0.09113,"epssPercentile":0.95141,"exploits":{"github":1,"githubRepos":["https://github.com/m0nk3ygod/CVE-2026-34040-PoC"],"checkedAt":"2026-09-21T15:48:23.867Z"},"exploitAvailable":true,"aliases":["GHSA-x744-4wpc-v9h2","GO-2026-4887"],"ecosystem":"go","ingestedAt":"2026-08-24T19:25:44.774Z","slug":"CVE-2026-34040","body":"## Overview\n\nA flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container environment. The bypass of these plugins can lead to unauthorized operations and potential compromise of the system's integrity and confidentiality.\n\n## Vendor advisories\n\n- **RHSA-2026:22347** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22347)\n- **RHSA-2026:67516** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67516)\n- **RHSA-2026:23345** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23345)\n- **RHSA-2026:24503** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24503)\n- **RHSA-2026:67842** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67842)\n- **RHSA-2026:21769** · Red Hat · fixed in: Red Hat multicluster global hub 1.5.3 · released 2026-05-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:21769)\n- **Red Hat VEX** · Moderate · affected: Multicluster Engine for Kubernetes, Red Hat Ceph Storage 5, Red Hat OpenShift Container Platform 4 · no fix planned: Multicluster Engine for Kubernetes, Red Hat Ceph Storage 5, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34040.json)\n\n**Moby: Moby: Authorization bypass vulnerability** — rated Moderate by Red Hat. Released 2026-03-31, updated 2026-09-21.\n\nAffected:\n\n- Multicluster Engine for Kubernetes\n- Red Hat Ceph Storage 5\n- Red Hat OpenShift Container Platform 4\n\nFixed:\n\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.6.5\n- Multicluster Global Hub 1.7.3\n- Red Hat multicluster global hub 1.5.3\n\nNo fix planned:\n\n- Multicluster Engine for Kubernetes\n- Red Hat Ceph Storage 5\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.6.5\n- Multicluster Global Hub 1.7.3\n- Red Hat multicluster global hub 1.5.3\n- Multicluster Engine for Kubernetes\n- OpenShift Service Mesh 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Virtualization 4\n\n## Remediation\n\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:22347\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:67516\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:23345\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-34040)\n\nAffected packages:\n\n- `github.com/moby/moby < 29.3.1`\n- `github.com/moby/moby/v2 < 2.0.0-beta.8`\n\nPatched in:\n\n- `github.com/moby/moby 29.3.1`\n- `github.com/moby/moby/v2 2.0.0-beta.8`\n\nSource: https://osv.dev/vulnerability/GHSA-x744-4wpc-v9h2","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":46.2,"likelihood":1.8,"exploitation":12,"ransomware":0},"changes":[{"seq":5120,"id":"CVE-2026-34040","ts":1788887248928,"field":"exploit_available","old":"false","new":"true"},{"seq":5119,"id":"CVE-2026-34040","ts":1788887248928,"field":"cvss","old":"8.8","new":"8.4"},{"seq":4003,"id":"CVE-2026-34040","ts":1788886364604,"field":"exploit_available","old":"true","new":"false"},{"seq":4002,"id":"CVE-2026-34040","ts":1788886364604,"field":"cvss","old":"8.4","new":"8.8"},{"seq":3227,"id":"CVE-2026-34040","ts":1788883134990,"field":"cvss","old":"8.8","new":"8.4"},{"seq":2815,"id":"CVE-2026-34040","ts":1788883031301,"field":"exploit_available","old":"false","new":"true"},{"seq":1844,"id":"CVE-2026-34040","ts":1788882434227,"field":"exploit_available","old":"true","new":"false"},{"seq":942,"id":"CVE-2026-34040","ts":1788881868249,"field":"exploit_available","old":"false","new":"true"}]}