CVE-2026-33997 is a high-severity vulnerability affecting Moby (Docker) versions prior to 29.3.1, allowing a privilege validation bypass during plugin installation. This flaw enables an attacker to remotely install a plugin with privileges beyond what the user approved, due to an error in the daemon's comparison logic. Rated 8.1 CVSS, it has low attack complexity and requires user interaction, potentially leading to high confidentiality and integrity compromise. While currently on a "Hot List," there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. It is not listed in CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 29.3.1CPE matchmatch criteria | cpe:2.3:a:docker:engine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.