CVE-2026-34040
Red Hat Security Advisory: Multicluster Global Hub 1.7.1 security update
Description
A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container environment. The bypass of these plugins can lead to unauthorized operations and potential compromise of the system's integrity and confidentiality.
Metrics
Weakness classes (CWE)
CWE-288Base
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Reanalysis2026-06-16 14:47 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* versions up to (excluding) 29.3.1 → OR *cpe:2.3:a:docker:engine:*:*:*:*:*:*:*:* versions up to (excluding) 29.3.1
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
apache
thrift0.23.0
bitnami
golang1.26.0-0
bitnami
grafana-pyroscope1.16.0
go
github.com/gomarkdown/markdown
go
github.com/moby/moby
go
github.com/moby/moby/v2
go
golang.org/x/image
grafana
tempo1.3.0 – 2.8.4
grafana
tempo2.10.0 – 2.10.2
grafana
tempo2.9.0 – 2.9.2
jackc
pgx5.9.0
jackc
pgx
openfga
openfga0.1.4 – 1.14.0
References & sources
- https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2advisory
- https://github.com/moby/moby/commit/e89edb19ad7de0407a5d31e3111cb01aa10b5a38fix
- https://docs.docker.com/engine/extend/plugins_authorizationweb
- https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fqweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-34040advisory
- https://github.com/moby/mobypackage
- https://github.com/moby/moby/releases/tag/docker-v29.3.1web
- https://pkg.go.dev/vuln/GO-2026-4772
- https://access.redhat.com/security/cve/CVE-2026-33816vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2455972issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33816.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:41019vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:17789vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:36796vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19137vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:26636vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22423vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:24503vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:24539vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25273vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-43869
A flaw was found in Apache Thrift.
highCVSSv3 7.3 - CVE-2026-41602
A flaw was found in the Apache Thrift TFramedTransport Go language implementation.
highCVSSv3 7.5 - CVE-2026-40890
A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML.
highCVSSv3 7.5 - CVE-2026-40293
A flaw was found in OpenFGA, an authorization/permission engine.
mediumCVSSv3 6.5 - CVE-2026-33816
A flaw was found in github.com/jackc/pgx, a PostgreSQL driver for Go.
criticalCVSSv3 9.8 - CVE-2026-33815
A flaw was found in github.com/jackc/pgx.
criticalCVSSv3 9.8 - CVE-2026-33813
A flaw was found in golang.org/x/image.
highCVSSv3 7.5 - CVE-2026-32282
A flaw was found in the internal/syscall/unix package in the Go standard library.
mediumCVSSv3 6.4 - CVE-2026-32281
A flaw was found in Go's `crypto/x509` package.
highCVSSv3 7.5 - CVE-2026-21728
A flaw was found in Tempo.
highCVSSv3 7.5 - CVE-2025-41118
Pyroscope is an open-source continuous profiling database.
criticalCVSSv3 9.1