Review reviewHigh

CVE-2026-33997

moby moby, Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.4.4

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.

CVSS
8.1
EPSS
0.39%
31.5% percentile
CISA KEV
Not listed
Published
2026.03.31
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.39%
Technical severityCVSS 8.1

Vulnerability overview

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.

Affected product and versions

Product
moby moby, Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.4.4
Affected versions
>= < 29.3.1, < 29.3.1
Fixed versions
29.3.1

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that moby moby, Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.4.4 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE
CWE-193, CWE-266
CVE-2026-33997 — moby moby, Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.4.4 | SECUFOCUS NOW