boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-33997HIGH
Moby: Off-by-one error in plugin privilege validation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  N    8.1   .0039   32.0     —
AFFECTED
  Product  Versions    Fixed
  moby     < 29.3.1 –  —
TIMELINE
  Mar 24  Reserved by GitHub_M
  Mar 31  Published (CNA: GitHub_M)
  Aug 17  RESCORED — CVE-2026-33997 (moby). CVSS 6.8 → 8.1 (NVD).
CWE-193 · CNA: GitHub_M · CVSS v3.1 · 8 references · NVD status: Modified

Description

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 24, 2026ReservedReserved by GitHub_M
March 31, 2026PublishedPublished (CNA: GitHub_M)
August 17, 2026RESCOREDRESCORED — CVE-2026-33997 (moby). CVSS 6.8 → 8.1 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
mobymoby< 29.3.1

Weaknesses

CWE-193

References (8)

Related

Authoritative record: CVE-2026-33997 at cve.org

Vendors: moby

Weaknesses: CWE-193

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-33997 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.