Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilitypatch-regressionidentity-authentication-vulnerability

Docker Engine AuthZ Bypass Flaw Enables Host Access via Oversized API Requests

Updated 3mo agoFirst seen Apr 7, 20264 sources

Docker disclosed a high-severity Docker Engine vulnerability, CVE-2026-34040 (CVSS 8.8), that allows attackers to bypass authorization plugins and perform actions that should be blocked. The flaw stems from an incomplete fix for CVE-2024-41110 and is triggered when a specially crafted oversized Docker API request causes the request body to be dropped before inspection by an AuthZ plugin. In affected environments, the plugin may approve container operations it would otherwise deny, opening a path to unauthorized privileged actions and potential host compromise.

Researchers said an attacker with Docker API access could exploit the bug by padding a container-creation request beyond 1 MB to launch a privileged container with access to the host filesystem, exposing sensitive assets such as AWS credentials, SSH keys, and Kubernetes configurations. The issue affects deployments that rely on authorization plugins inspecting request bodies, while environments not using those plugins are not impacted. Docker patched the vulnerability in Docker Engine 29.3.1 and urged defenders to upgrade, restrict Docker API access, avoid AuthZ plugins that depend on request-body inspection, and use controls such as rootless mode, user namespace remapping, and least-privilege access to reduce risk.

Share:
Docker Engine AuthZ Bypass Flaw Enables Host Access via Oversized API Requests
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 7, 20263mo ago

Docker releases Docker Engine 29.3.1 to patch CVE-2026-34040

Docker fixed the vulnerability in Docker Engine version 29.3.1. It also recommended mitigations including avoiding AuthZ plugins that depend on request-body inspection, restricting Docker API access, and using rootless mode or user namespace remapping to reduce impact.

Cyera warns AI coding agents could trigger the Docker bypass

Cyera Research Labs warned that AI coding agents operating in Docker-based sandboxes could be induced, or could independently infer how, to exploit CVE-2026-34040 and escalate access. This added a new exploitation scenario to the vulnerability's public understanding.

Researchers detail host-access risks from crafted oversized Docker API requests

Reporting on the disclosure explained that an attacker with Docker API access could pad a container creation request beyond 1 MB to create a privileged container with host filesystem access. The described impact includes potential exposure of sensitive assets such as AWS credentials, SSH keys, and Kubernetes configuration data.

Docker discloses CVE-2026-34040 authorization bypass flaw

Docker disclosed a high-severity Docker Engine vulnerability, CVE-2026-34040 (CVSS 8.8), that allows authorization plugin bypass in certain configurations. The issue involves oversized API requests whose bodies are not properly forwarded to AuthZ plugins, enabling unauthorized actions and possible host compromise.

Docker's earlier CVE-2024-41110 fix leaves an incomplete remediation

Docker's later advisory for CVE-2026-34040 states the new flaw stems from an incomplete fix for CVE-2024-41110, establishing the earlier remediation as the precursor event. No specific date for that earlier fix is provided in the references.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Affected products
4 linked
GithubKubernetesDocker EngineOpenclaw
Organizations
6 linked
Amazon Web ServicesLinkedinCyeraXDockerGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.