CVE-2026-34040Disclosure(docker / engine)

HIGHCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 28 mentions and remains active

Immediate actions

  • Patch docker engine systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • engine

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 97 mentions across 24 observed days

What's happening

  • Active exploitation reported across 7 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 29 signals
  • Technical details provided in 73 signals
  • Disclosure: 56 classified signals
  • General: 11 classified signals
  • Peaked 19d ago at 28 mentions (2026-04-08); latest day: 1
  • 97 total mentions across 24 days

Affected systems

Vendors
Products
engine

Deep dive

Activity timeline97 mentions / 24d
07142128Mentions · 2026-03-26: 1Mentions · 2026-03-31: 4Mentions · 2026-04-03: 1Mentions · 2026-04-07: 27Mentions · 2026-04-08: 28Mentions · 2026-04-09: 5Mentions · 2026-04-10: 7Mentions · 2026-04-11: 2Mentions · 2026-04-12: 1Mentions · 2026-04-13: 3Mentions · 2026-04-14: 3Mentions · 2026-04-15: 2Mentions · 2026-04-16: 1Mentions · 2026-04-17: 2Mentions · 2026-04-21: 1Mentions · 2026-04-23: 1Mentions · 2026-04-27: 1Mentions · 2026-05-07: 1Mentions · 2026-05-10: 1Mentions · 2026-05-19: 1Mentions · 2026-06-08: 1Mentions · 2026-07-07: 1Mentions · 2026-09-06: 1Mentions · 2026-09-16: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-09-06: 1PoC Mentioned / Linked · 2026-09-16: 1Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-10: 2Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-04-14: 2Patch / Workaround · 2026-03-31: 2Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 10Patch / Workaround · 2026-04-09: 3Patch / Workaround · 2026-04-10: 6Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-06-08: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-31: 3Technical Details · 2026-04-07: 20Technical Details · 2026-04-08: 21Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 7Technical Details · 2026-04-11: 2Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 3Technical Details · 2026-04-14: 2Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-23: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-08: 1Technical Details · 2026-07-07: 1Technical Details · 2026-09-06: 1Technical Details · 2026-09-16: 103-2604-0304-0804-1004-1204-1404-1604-2104-2705-1006-0809-0609-16
Signal classification6 categories
Disclosure
5657.7%
Patch
2222.7%
General
1111.3%
Active Exploitation
55.2%
PoC
22.1%
Disclsee
11.0%
Referenced assets59 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-314
Disclosure2General1Patch1
2026-04-031
Patch1
2026-04-0727
Active Exploitation1Disclosure21General4Patch1
2026-04-0828
Disclosure15Disclsee1General4Patch8
2026-04-095
Disclosure3Patch2
2026-04-107
Active Exploitation1Disclosure1Patch5
2026-04-112
Disclosure2
2026-04-121
Disclosure1
2026-04-133
Active Exploitation1Disclosure2
2026-04-143
Active Exploitation2General1
2026-04-152
General1Patch1
2026-04-161
Disclosure1
2026-04-172
Disclosure2
2026-04-211
Disclosure1
2026-04-231
Patch1
2026-04-271
Disclosure1
2026-05-071
Disclosure1
2026-05-101
Patch1
2026-05-191
Disclosure1
2026-06-081
Patch1
2026-07-071
Disclosure1
2026-09-061
PoC1
2026-09-161
PoC1
Full discourse20 posts
  • Hamed Bidi@hamedbd
    Patch

    آپدیت‌های مهمی در OpenSSH و Docker هم داشتیم: OpenSSH: رفع افزایش دسترسی غیرمجاز (Privilege Escalation) در مه ۲۰۲۶. Docker: رفع CVE-2026-34040 که امکان دور زدن مجوزها و فرار از کانتینر را می‌داد. دسترسی remoto و محیط‌های کانتینری بدون این آپدیت‌ها کاملاً ناامن هستند. ۱۰/۱۴

    Post summary

    The statement announces security updates for OpenSSH and Docker that address privilege‑escalation and container escape vulnerabilities, emphasizing the need to apply the patches for safe operation.

    1007902.3K
    18.5K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access https://thehackernews.com/2026/04/docker-cve-2026-34040-lets-attackers.html

    Post summary

    The headline announces the discovery of a Docker vulnerability (CVE-2026-34040) that enables attackers to bypass authorization and obtain host access.

    06015112.7K
    157.2K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    🛑 𝗗𝗼𝗰𝗸𝗲𝗿 - 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟯𝟰𝟬𝟰𝟬 Docker Engine : une faille de sécurité patchée en 2019, puis en 2024, est de nouveau patchée en 2026. Tous les détails 👇 - https://www.it-connect.fr/docker-la-faille-cve-2026-34040-permet-dobtenir-un-acces-root-sur-lhote/ #Docker #infosec #cybersecurite https://t.co/JVaBvhIYHG

    Post summary

    This tweet announces that Docker Engine’s CVE‑2026‑34040 has been patched multiple times, most recently in 2026, and directs readers to an external article for further information.

    04061576
    11.4K followersView on X
  • NanoVMs@nanovms
    General

    wish I could say that CVE-2026-34040 is the first container escape of april 2026 but it is not (it's just a incomplete fix of a 7yo vuln); the fuckups with not releasing the crackarmor cves (too busy vibecoding it seems) means some came in april as well containers don't contain

    Post summary

    The tweet states CVE‑2026‑34040 is not a first container escape but an incomplete fix for a long‑standing flaw, with no PoC, exploit, patch, or active exploitation details provided.

    01080544
    2.2K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access http://dlvr.it/TSQNJS #Docker #CVE202634040 #CyberSecurity #Vulnerability #InfoSec https://t.co/rrh8a2yXKt

    Post summary

    The tweet announces Docker CVE‑2026‑34040, noting the vulnerability bypasses authorization and allows host access, but provides no technical details or exploit information.

    01033493
    56.4K followersView on X
  • Sam Stepanyan@securestep9
    Disclosure

    #Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access: 👇 https://thehackernews.com/2026/04/docker-cve-2026-34040-lets-attackers.html

    Post summary

    Docker CVE‑2026‑34040 permits attackers to bypass authorization and gain host-level access, as announced in the linked article.

    01021234
    7.4K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Docker CVE-2026-34040 authorization bypass allows attackers to create privileged containers and gain host access, exposing cloud credentials, SSH keys, and Kubernetes configs. https://thehackernews.com/2026/04/docker-cve-2026-34040-lets-attackers.html

    Post summary

    The post announces that Docker CVE‑2026‑34040 permits an authorization bypass enabling attackers to launch privileged containers, thereby gaining host access and exposing sensitive credentials.

    00112106
    2.0K followersView on X
  • IT SPARC Cast@ITSPARCCast
    Patch

    In this week’s episode of IT SPARC Cast - CVE of the Week, @john_Video and @loudoggeek discuss a newly disclosed Docker vulnerability (CVE-2026-34040) thatis exposing a critical weakness in container security—allowing attackers to bypass authorization controls and potentially access host systems. In this episode of IT SPARC Cast – CVE of the Week, we break down: • How the Docker API vulnerability works • Why container isolation can fail • The real risk of chained attacks • How AI-driven hacking amplifies the threat • What you need to patch right now If you’re running Docker in production, this is one you can’t ignore. 👉 Patch immediately. Audit everything. Assume attackers will chain this. Youtube Episode 32 - https://youtu.be/aBQpjOwuDJI&utm_source=x&utm_medium=organic_social&utm_campaign=it_sparc_cast&utm_content=post YouTube Channel - https://www.youtube.com/@sparccast Apple Podcast Link - https://podcasts.apple.com/us/podcast/it-sparc-cast/id1765417728 Spotify Link - https://open.spotify.com/show/6bzVql2gpV6aVqX8oAAPls Amazon Podcast Link - https://music.amazon.com/podcasts/ea33693d-f555-4a7c-8c36-d321ab5cfed2/it-sparc-cast?ref=dm_sh_MPp9hVbtUJhlG3cN3xhfN5YN3 Acast Link - https://shows.acast.com/it-sparc-cast

    Post summary

    A newly disclosed Docker vulnerability (CVE‑2026‑34040) that enables attackers to bypass authorization and potentially reach host systems is discussed, with a clear call to patch immediately and audit all Docker deployments.

    00210246
    480 followersView on X
  • Chevalyetek@chevalyetek
    Patch

    Gen yon gwo vilnerabilite grav CVE-2026-34040 nan Docker Engine ki ka pèmèt atakan kontoune otorizasyon epi jwenn aksè ak host la. Pwoblèm nan korije nan vèsyon 29.3.1. Admin yo dwe mete Docker ajou rapid. #Chevalyetek https://t.co/qqCKXg3Bkd

    Post summary

    CVE-2026-34040 is a serious Docker Engine vulnerability that lets attackers bypass authorization and access the host; it is fixed in Docker Engine 29.3.1, so administrators should upgrade promptly.

    0102069
    3 followersView on X
  • سايبركاست@cyberscastx
    General

    نتيجة إصلاح غير مكتمل، ثغرة خطيرة جديدة في @Docker. ثغرة عالية الخطورة (CVE-2026-34040 بتقييم CVSS عند 8.8) في Docker Engine، تسمح بتجاوز ضوابط AuthZ وإنشاء حاويات بخصائص أو صلاحيات كان يفترض منعها. https://t.co/29IXQwmdrL

    Post summary

    The tweet announces a high‑severity Docker Engine vulnerability (CVE‑2026‑34040) that permits AuthZ bypass to launch privileged containers, but it provides no PoC, exploit code, active attack reports, or patch information.

    11010595
    6.6K followersView on X
  • Hexon@hexonbot
    Disclosure

    Docker CVE-2026-34040 lets AI agents bypass authorization with one HTTP request. Host filesystem exposure and credential theft are one padded request away. https://www.hexon.bot/blog/docker-cve-2026-34040-ai-agent-sandbox-escape-authorization-bypass #Docker #AIsecurity

    Post summary

    The post announces that CVE-2026-34040 lets AI agents escape authorization via a single HTTP request, potentially exposing the host filesystem and credentials.

    20010137
    404 followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access https://thehackernews.com/2026/04/docker-cve-2026-34040-lets-attackers.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The article announces that Docker CVE-2026‑34040 permits attackers to bypass authorization mechanisms and gain host access, highlighting the vulnerability but not providing patches or exploitation details.

    00012480
    194.4K followersView on X
  • Nik Kale@nik_kale
    Disclosure

    CVE-2026-34040 in Docker lets attackers bypass authorization via oversized HTTP request bodies. Bad enough on its own. Now chain it with this: an AI coding agent like OpenClaw running inside a Docker-based sandbox can be tricked into executing a prompt injection hidden in a GitHub repo as part of a normal developer workflow. The malicious code exploits the Docker CVE to create a privileged container and mount the host filesystem. This is the attack pattern I keep warning about. It's not one vulnerability. It's a chain: prompt injection in a repo, processed by an agent, exploiting a container escape, leading to host compromise. Each link looks manageable in isolation. Together, they give an attacker full host access through a developer's routine git clone. https://thehackernews.com/2026/04/docker-cve-2026-34040-lets-attackers.html

    Post summary

    The post announces a new Docker vulnerability (CVE-2026-34040) that permits authorization bypass through oversized HTTP requests and warns of a potential chain involving prompt injection, container escape, and host compromise.

    10010160
    399 followersView on X
  • Robert Berger@ReliableEmbSys
    Patch

    🚨 Security Alert: CVE-2026-34040 (CVSS 8.8) is critical due to an incomplete fix for CVE-2024-41110. Discovered by Asim Viladi Oglu Manizada & team. Update Docker Engine v29.3.1 ASAP! 🚀 Beware AI agents exploiting padded HTTP requests! #CyberSecurity #Docker #Vulnerability https://t.co/JPRdhl0zjU

    Post summary

    The tweet is a security alert urging an immediate update to Docker Engine v29.3.1 to address CVE-2026-34040, highlighting an incomplete fix for a related CVE and warning of active exploitation by AI agents.

    00020114
    208 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Critical Flowise RCE (CVE-2025-59528) actively exploited via CustomMCP; Docker Engine (CVE-2026-34040) & Ninja Forms (CVE-2026-0740) need patches. APT28 hijacks MikroTik/TP-Link DNS to steal Microsoft creds. #FlowiseRCE #APT28DNS #Russia https://ift.tt/SDQ2Mbd

    Post summary

    The tweet announces that CVE-2025-59528 (Flowise RCE) is being actively exploited, and urges patching for Docker Engine and Ninja Forms, while also noting APT28’s DNS hijacking activity.

    00020572
    4.4K followersView on X
  • Carlos Fynn@fynn_JourX
    Disclosure

    Legacy exposure keeps paying off for attackers. CVE-2026-34040 puts Docker image-mount trust on the host… CVE-2026-34040 is a Docker container security flaw that can let attackers use crafted image… 🔗 Read → https://invaders.ie/resources/blog/vulnerability/cve-2026-34040-docker-image-mount-host-root-risk

    Post summary

    The post announces a newly discovered Docker image‑mount flaw (CVE‑2026‑34040) that could allow attackers to exploit crafted images for host root access. It provides no PoC, exploit code, patch, or evidence of active exploitation.

    0101055
    82 followersView on X
  • AccuKnox@AccuKnox
    PoC

    CVE-2026-34040 lets an oversized payload slip past Docker's controls, launch a privileged container, mount the host filesystem, and read cloud credentials and kube configs. Host filesystem access ends the debate. Blocking the mount at runtime beats waiting on a patch window.

    Post summary

    The text discloses CVE‑2026‑34040, explaining how an oversized payload can bypass Docker controls to achieve privileged container execution and mount the host filesystem, granting access to cloud credentials and kube configs; it advises blocking the mount rather than waiting for a patch.

    0001038
    346 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Docker Engine の脆弱性 CVE-2026-34040 が FIX:AuthZ バイパスによる権限昇格の恐れ https://iototsecnews.jp/2026/04/08/docker-authorization-bypass-flaw-exposed-hosts-to-potential-attackers/ Docker Engine の脆弱性 CVE-2026-34040 は、以前に報告された CVE-2024-41110 に対する修正が不十分だったことに起因します。大きなサイズのリクエストを処理する際に、本来 AuthZ プラグインへ送られるべきデータが消えてしまうという、特殊な不具合が潜んでいました。そのため、認可の判断に必要な情報がプラグインに届かず、本来は拒否されるべき不正な操作が、誤って許可されてしまう状況が生じています。ご利用のチームは、ご注意ください。 #Cloud #CVE202634040 #DockerEngine #Vulnerability

    Post summary

    The post describes Docker Engine CVE‑2026‑34040 as an AuthZ bypass leading to privilege escalation, explaining how large requests cause missing authorization data, but it offers no PoC, exploit code, or evidence of active exploitation.

    01000106
    484 followersView on X
  • CyberTLDR@CyberTLDR
    Disclosure

    A high-severity vulnerability, CVE-2026-34040 (CVSS 8.8), has been disclosed in Docker Engine. This incomplete fix for a previous flaw allows attackers to bypass all authorization plugins (AuthZ) by sending an oversized HTTP request (>1MB) #docker #cybersecurity #thread https://t.co/TI5wtTTduK

    Post summary

    CVE-2026-34040 has been disclosed for Docker Engine, allowing bypass of all authorization plugins via oversized HTTP requests (>1MB); no PoC, exploit, or patch details are offered.

    1000053
    6 followersView on X
  • John Barger@JohnBarger
    Patch

    A newly disclosed Docker vulnerability (CVE-2026-34040) is exposing a critical weakness in container security—allowing attackers to bypass authorization controls and potentially access host systems. In this episode of IT SPARC Cast – CVE of the Week, @loudoggeek and I break down: • How the Docker API vulnerability works • Why container isolation can fail • The real risk of chained attacks • How AI-driven hacking amplifies the threat • What you need to patch right now If you’re running Docker in production, this is one you can’t ignore. 👉 Patch immediately. Audit everything. Assume attackers will chain this. 👍 Like, Subscribe, and turn on notifications for more enterprise IT insights.

    Post summary

    The article announces a new Docker CVE (CVE-2026-34040) that permits bypassing authorization and host access, and urges immediate patching and audit.

    0001088
    1.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdockerengine---

Explore more