---
id: CVE-2026-34040
title: 'Moby: Moby: Authorization bypass vulnerability (CVE-2026-34040)'
summary: >-
  A flaw was found in Moby, an open-source container framework. This security
  vulnerability allows attackers to bypass authorization plugins (AuthZ), which
  are mechanisms designed to control access and permissions within the container
  enviro…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-807
vendor: Red Hat
product: Multicluster Global Hub 1.4.9
affected:
  - multicluster_engine_for_kubernetes
  - ceph_storage 5
  - openshift_container_platform 4
  - multicluster_global_hub 1.4.9
  - multicluster_global_hub 1.6.5
  - multicluster_global_hub 1.7.3
  - multicluster_global_hub 1.5.3
patched:
  - multicluster_global_hub 1.4.9
  - multicluster_global_hub 1.6.5
  - multicluster_global_hub 1.7.3
  - multicluster_global_hub 1.5.3
published: '2026-03-31'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T11:29:30+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34040.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34040.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-34040'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2453278'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-34040'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34040'
  - url: 'https://github.com/moby/moby/releases/tag/docker-v29.3.1'
  - url: 'https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22347'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67516'
  - url: 'https://access.redhat.com/errata/RHSA-2026:23345'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24503'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67842'
  - url: 'https://access.redhat.com/errata/RHSA-2026:21769'
  - url: 'https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq'
  - url: >-
      https://github.com/moby/moby/commit/e89edb19ad7de0407a5d31e3111cb01aa10b5a38
  - url: 'https://docs.docker.com/engine/extend/plugins_authorization'
  - url: 'https://github.com/moby/moby'
tags:
  - csaf
  - vex
  - red-hat
  - exploit-available
  - osv
  - go
epss: 0.09113
epssPercentile: 0.95082
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/m0nk3ygod/CVE-2026-34040-PoC'
  checkedAt: '2026-09-24T07:53:02.539Z'
exploitAvailable: true
aliases:
  - GHSA-x744-4wpc-v9h2
  - GO-2026-4887
ecosystem: go
ingestedAt: '2026-08-24T19:25:44.774Z'
---

## Overview

A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container environment. The bypass of these plugins can lead to unauthorized operations and potential compromise of the system's integrity and confidentiality.

## Vendor advisories

- **RHSA-2026:22347** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22347)
- **RHSA-2026:67516** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67516)
- **RHSA-2026:23345** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23345)
- **RHSA-2026:24503** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24503)
- **RHSA-2026:67842** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67842)
- **RHSA-2026:21769** · Red Hat · fixed in: Red Hat multicluster global hub 1.5.3 · released 2026-05-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:21769)
- **Red Hat VEX** · Moderate · affected: Multicluster Engine for Kubernetes, Red Hat Ceph Storage 5, Red Hat OpenShift Container Platform 4 · no fix planned: Multicluster Engine for Kubernetes, Red Hat Ceph Storage 5, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34040.json)

**Moby: Moby: Authorization bypass vulnerability** — rated Moderate by Red Hat. Released 2026-03-31, updated 2026-09-21.

Affected:

- Multicluster Engine for Kubernetes
- Red Hat Ceph Storage 5
- Red Hat OpenShift Container Platform 4

Fixed:

- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.6.5
- Multicluster Global Hub 1.7.3
- Red Hat multicluster global hub 1.5.3

No fix planned:

- Multicluster Engine for Kubernetes
- Red Hat Ceph Storage 5
- Red Hat OpenShift Container Platform 4

Not affected:

- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.6.5
- Multicluster Global Hub 1.7.3
- Red Hat multicluster global hub 1.5.3
- Multicluster Engine for Kubernetes
- OpenShift Service Mesh 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Virtualization 4

## Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:22347
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:67516
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:23345

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-34040)

Affected packages:

- `github.com/moby/moby < 29.3.1`
- `github.com/moby/moby/v2 < 2.0.0-beta.8`

Patched in:

- `github.com/moby/moby 29.3.1`
- `github.com/moby/moby/v2 2.0.0-beta.8`

Source: https://osv.dev/vulnerability/GHSA-x744-4wpc-v9h2
