8.8
CVE-2026-34040
- EPSS 0.01%
- Published 31.03.2026 01:36:48
- Last modified 03.04.2026 16:51:28
- Source security-advisories@github.com
- CVE watchlists
- Open
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
Data is provided by the National Vulnerability Database (NVD)
Mobyproject ≫ Moby Version < 29.3.1
| Type | Source | Score | percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.024 |
| Source | Base Score | Exploit Score | Impact Score | Vector string |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| security-advisories@github.com | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-288 Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.