CVE-2026-33997Disclosure(docker / engine)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch docker engine systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-193CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • engine

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-31)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
engine

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-26: 1Mentions · 2026-03-31: 2Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-31: 203-2603-31
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-312
Disclosure1General1
Full discourse3 posts
  • Paweł Gronowski@grono_dev
    Disclosure

    CVE-2026-33997 / GHSA-pxq6-2prw-chj9 "docker plugin install" privilege validation bypass: the daemon did not fully enforce plugin privilege checks in some cases, creating a path to unintended privilege escalation. Relevant if you install or manage Docker plugins.

    Post summary

    A new privilege validation bypass (CVE‑2026‑33997) in Docker exposes an unintended privilege escalation path during plugin installation. No PoC, exploit, or patch details are provided.

    1000026
    10 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33997 📊 Severity: 6.8 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33997 #CVE-2026-33997 #CVE #Medium #CyberSecurity #InfoSec https://t.co/f6qplzMETI

    Post summary

    A tweet announces CVE‑2026‑33997 with a CVSS score of 6.8 and a medium risk level, but offers no concrete technical details, exploit code, or patch information.

    0000029
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33997 Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypasse… https://www.cve.org/CVERecord?id=CVE-2026-33997

    Post summary

    The post announces CVE‑2026‑33997 for the Moby container framework, noting a plugin privilege‑validation bypass that affects versions before 29.3.1, which implies a patch is available in 29.3.1.

    0000076
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdockerengine---

Explore more