A high-severity security vulnerability has been disclosed in Docker Engine that could permit an attacker to bypass authorization plugins (AuthZ) under specific circumstances.
The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), stems from an incomplete fix for CVE-2024-41110, a maximum-severity vulnerability in the same component that came to light in July 2024.
“
The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), stems from an incomplete fix for CVE-2024-41110, a maximum-severity vulnerability in the same component that came to light in July 2024.
“



![[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk](https://encircle-it.com/wp-content/uploads/2026/04/webinar-how-to-close-identity-gaps-in-2026-before-ai-exploits-enterprise-risk.png)






