CVE Feed

    Dashboard / CVE / CVE-2026-33997

    CVE-2026-33997

    Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.

    Published:Mar 31, 2026
    Last Modified:Jun 16, 2026
    EPS:Mar 31, 2026
    EPSS Score:0.00315
    CVSS Score:6.8

    Affected Products

    Vendor
    Docker
    Product
    Engine
    Vendor
    Moby
    Product
    Moby

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High