8.8

CVE-2026-34040

Media report
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
Data is provided by the National Vulnerability Database (NVD)
MobyprojectMoby Version < 29.3.1
No CISA KEV or CERT.AT alert has been found for this CVE.
EPSS Metrics
Type Source Score percentile
EPSS FIRST.org 0.01% 0.024
CVSS Metrics
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.