CVE-2026-34040

Red Hat Security Advisory: Multicluster Global Hub 1.7.1 security update

Description

A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container environment. The bypass of these plugins can lead to unauthorized operations and potential compromise of the system's integrity and confidentiality.

Metrics

Severity
high
no public PoC known
8.8
Source: nvd-v3
95.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
9.1 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-06-08 14:02 UTC
CWE-288

Weakness classes (CWE)

  • CWE-288Base

    Authentication Bypass Using an Alternate Path or Channel

    The product requires authentication, but the product has an alternate path or channel that does not require authentication.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Reanalysis2026-06-16 14:47 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* versions up to (excluding) 29.3.1OR *cpe:2.3:a:docker:engine:*:*:*:*:*:*:*:* versions up to (excluding) 29.3.1

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apache

    thrift0.23.0

  • bitnami

    golang1.26.0-0

  • bitnami

    grafana-pyroscope1.16.0

  • go

    github.com/gomarkdown/markdown

  • go

    github.com/moby/moby

  • go

    github.com/moby/moby/v2

  • go

    golang.org/x/image

  • grafana

    tempo1.3.0 – 2.8.4

  • grafana

    tempo2.10.0 – 2.10.2

  • grafana

    tempo2.9.0 – 2.9.2

  • jackc

    pgx5.9.0

  • jackc

    pgx

  • openfga

    openfga0.1.4 – 1.14.0

References & sources

Linked CVEs

IDCVE-2026-34040