CVE-2026-34040High· 8.4▾ MidnightPoC availableA flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container enviro…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 46.2 · likelihood 1.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
9.6%
1 GitHub repo
8.8 → 8.4
8.4 → 8.8
8.8 → 8.4
Last analysed / modified upstream
A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container environment. The bypass of these plugins can lead to unauthorized operations and potential compromise of the system's integrity and confidentiality.
Moby: Moby: Authorization bypass vulnerability — rated Moderate by Red Hat. Released 2026-03-31, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:22347 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:67516 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:23345
Workarounds / mitigations:
Affected packages:
github.com/moby/moby < 29.3.1github.com/moby/moby/v2 < 2.0.0-beta.8Patched in:
github.com/moby/moby 29.3.1github.com/moby/moby/v2 2.0.0-beta.8Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53492High· 8.2github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…
CVE-2026-74959Critical· 9.1Mitigation bypass in the Storage: Cache API component
CVE-2026-74957High· 8.1Mitigation bypass in the Safe Browsing component
CVE-2026-56746High· 7.5io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746)
CVE-2026-16221High· 7.5fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221)
CVE-2026-8328Medium· 5.3The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed