Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Moby: Off-by-one error in plugin privilege validation
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R U H H N 8.1 .0039 32.0 —
AFFECTED
Product Versions Fixed
moby < 29.3.1 – —
TIMELINE
Mar 24 Reserved by GitHub_M
Mar 31 Published (CNA: GitHub_M)
Aug 17 RESCORED — CVE-2026-33997 (moby). CVSS 6.8 → 8.1 (NVD).
Description
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 24, 2026 | Reserved | Reserved by GitHub_M |
| March 31, 2026 | Published | Published (CNA: GitHub_M) |
| August 17, 2026 | RESCORED | RESCORED — CVE-2026-33997 (moby). CVSS 6.8 → 8.1 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| moby | moby | — | < 29.3.1 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-33997 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.