CVE-2026-33997Medium· 6.8▾ SunlitMoby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privile…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.
engine < 29.3.1Upgrade past the affected range:
engine 29.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-15467High· 8.1A flaw was found in the trustyai-service-operator's LMEvalJob controller
CVE-2026-91099Critical· 9.8HP has identified and remediated multiple externally reported vulnerabilities within HPLIP
CVE-2026-91100Critical· 9.8HP has identified and remediated multiple externally reported vulnerabilities within HPLIP
CVE-2026-91101Critical· 9.8HP has identified and remediated multiple externally reported vulnerabilities within HPLIP
CVE-2026-91103Critical· 9.8HP has identified and remediated multiple externally reported vulnerabilities within HPLIP
CVE-2026-91105Critical· 9.8HP has identified and remediated multiple externally reported vulnerabilities within HPLIP