Back to News
Vulnerabilities

Attackers Bypass Authorization on Docker and Gain Host Access

Cyber RTApril 9, 20263 min read
Attackers Bypass Authorization on Docker and Gain Host Access

A critical security vulnerability, CVE-2026-34040, in Docker Engine allows attackers to bypass authorization plugins using specially-crafted API requests. Stemming from an incomplete fix for CVE-2024-41110, this flaw enables the creation of privileged containers with host file system access. Discovered by multiple researchers, it affects systems relying on request body inspection for access control. Docker Engine version 29.3.1 patches the issue.

A high-severity security vulnerability, identified as CVE-2026-34040 with a CVSS score of 8.8, has been discovered in Docker Engine. This flaw allows attackers to bypass authorization plugins (AuthZ) under certain conditions. The vulnerability is linked to an incomplete fix for a previous critical vulnerability, CVE-2024-41110, which was disclosed in July 2024. Docker Engine maintainers have issued an advisory explaining that a specially crafted API request could cause the Docker daemon to forward the request to an authorization plugin without the body, potentially allowing unauthorized requests to be approved. The vulnerability affects users who rely on authorization plugins that inspect the request body for access control decisions. Several security researchers, including Asim Viladi Oglu Manizada, Cody, Oleh Konko, and Vladimir Tokarev, independently discovered and reported the bug. The issue has been addressed in Docker Engine version 29.3.1, which includes a patch to fix the vulnerability. According to Cyera Research Labs researcher Vladimir Tokarev, the vulnerability arises from the improper handling of oversized HTTP request bodies in the previous fix. This oversight enables attackers to exploit the system by sending a single padded HTTP request, which can create a privileged container with access to the host file system. This scenario poses a significant security risk, as it allows attackers to gain root access to sensitive information such as AWS credentials, SSH keys, and Kubernetes configurations. In a hypothetical attack scenario, an attacker with restricted Docker API access can bypass the AuthZ plugin by padding a container creation request to exceed 1MB. This causes the request to be dropped before reaching the plugin, allowing the Docker daemon to process it and create a privileged container. This method is effective against all AuthZ plugins in the ecosystem, as they fail to block the request without the body. The vulnerability also poses a threat to AI coding agents like OpenClaw, which operate within Docker-based sandboxes. These agents can be manipulated into executing a prompt injection hidden within a crafted GitHub repository. This results in the execution of malicious code that exploits CVE-2026-34040 to bypass authorization and create a privileged container, thus mounting the host file system. Cyera warns that AI agents could independently discover and exploit this bypass by constructing a padded HTTP request when encountering errors during legitimate debugging tasks. This eliminates the need for a malicious repository, as the agents can leverage their understanding of the Docker API to exploit the vulnerability without additional tools or privileges. To mitigate the risk, it is recommended to avoid using AuthZ plugins that depend on request body inspection for security decisions. Access to the Docker API should be restricted to trusted parties, adhering to the principle of least privilege. Alternatively, running Docker in rootless mode can reduce the impact of a potential breach, as it maps a privileged container's 'root' to an unprivileged host UID. For environments unable to fully adopt rootless mode, the --userns-remap option offers a similar UID mapping solution.