
CVE-2026-33997 / GHSA-pxq6-2prw-chj9 "docker plugin install" privilege validation bypass: the daemon did not fully enforce plugin privilege checks in some cases, creating a path to unintended privilege escalation. Relevant if you install or manage Docker plugins.
Post summary
A new privilege validation bypass (CVE‑2026‑33997) in Docker exposes an unintended privilege escalation path during plugin installation. No PoC, exploit, or patch details are provided.


