people · May 19, 2026
Docker Security Team Addresses CVE-2026-34040 in Docker Engine 29.3.1
Share the canonical public link.
Cyera Research disclosed authorization bypass vulnerability CVE-2026-34040 affecting Docker Engine. The flaw impacts 92% of enterprise deployments and over 20 billion container image pulls per month. Patch released in Docker Engine 29.3.1 with confirmation against versions up to 27.5.1. The issue bypasses every AuthZ plugin including OPA Prisma Cloud and Casbin.
Below validation threshold — auto-passed without scoring