Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-34040-PoC | Kitploit
Tools/GitHubGitHub/m0nk3ygod/cve-2026-34040-poc
Cloud Infrastructure SecurityContainer SecurityVulnerability AnalysisExploitationLearning & EducationLabs & Practice
GitHubm0nk3ygod/cve-2026-34040-poc

CVE-2026-34040-PoC

View Repository
2 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-34040 — Docker/Moby AuthZ Plugin Bypass (Lab PoC)

EN: A lab reproduction of a vulnerability that bypasses Docker (Moby) authorization (AuthZ) plugins using an oversized (>1MB) request body.

Vulnerability facts

ItemValue
CVECVE-2026-34040
CVSS 3.18.8 (High) — CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWECWE-288 (Authentication Bypass Using an Alternate Path or Channel), CWE-863 (Incorrect Authorization)
Affectedmoby/moby < 29.3.1, docker/docker < 29.3.1, moby/moby/v2 < 2.0.0-beta.8
Fixed in29.3.1, 2.0.0-beta.8
Root causeIncomplete fix for CVE-2024-41110
Patch commitmoby/moby@e89edb1

EN: The official CVSS vector is AV:L (Local). The rated scenario is a low-privileged user with local Docker API access (typically /var/run/docker.sock). This PoC uses the local UNIX socket only.

What this demonstrates

EN:

  1. A normal-sized privileged container-create request is blocked by the AuthZ plugin (HTTP 403).
  2. The same request padded beyond 1MB bypasses the AuthZ check.
  3. The bypassed request reaches the Docker daemon and creates a privileged container.
  4. With privileged + host bind mount, host file read and host command execution can be demonstrated.

EN: The CVE itself does not read /etc/shadow or perform RCE directly. The vulnerability is the bypass of a Docker API request that AuthZ should block; the later steps (file read, chroot, command execution) are impact demos that abuse normal Docker/Linux features.

Repository structure

root@kitploit:~
.
├── README.md
├── poc.py                  # Working PoC (local UNIX socket only)
├── requirements.txt        # Python standard library only
├── LICENSE
├── lab/
│   ├── authz.rego          # OPA policy: blocks privileged + host-root bind
│   └── daemon.json         # Registers the AuthZ plugin
└── docs/
    ├── concepts.md         # 개념 / Concepts
    ├── lab-setup.md        # 환경 구성 / Lab setup
    ├── how-it-works.md     # 동작 원리 / How it works (source-level)
    ├── usage.md            # 사용법 / Usage
    ├── troubleshooting.md  # 문제 해결 / Troubleshooting
    └── references.md       # 참고 / References

Prerequisites

Quick start

root@kitploit:~
# 1) Pull the image used by the PoC
sudo docker pull alpine

# 2) Run the non-destructive bypass check
sudo python3 poc.py --mode check

Expected on a vulnerable target:

root@kitploit:~
small request     -> HTTP 403   (AuthZ blocks)
oversized request -> HTTP 201 or HTTP 404   (AuthZ bypassed; daemon processed it)

EN: A 404 No such image is still evidence of bypass — the request passed AuthZ (not 403) and reached the daemon's image lookup. Pull alpine beforehand to avoid confusion in a demo.

See docs/usage.md for full usage.

Lab-only warning

EN: Use only in an isolated lab you own or are explicitly authorized to test. Do not run against remote Docker APIs, third-party servers, production, or internet-exposed Docker endpoints. The impact-demo modes (rce-proof, host-command, reverse-shell-local) require an explicit confirmation flag.

References

See docs/references.md.

Download Tool
ConditionRequiredReason
Local Docker API access (/var/run/docker.sock)YesThe PoC sends requests to the socket
AuthZ plugin enabled with a body-inspecting policyYesThe bypass target is the AuthZ check
Docker/Moby < 29.3.1YesPatched versions reject oversized bodies
alpine image present locallyRecommendedOtherwise create returns 404 No such image