GHSA-frhv-529m-5v9vHigh
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow...
🔗 CVE IDs covered (1)
📋 Description
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent
access on the host.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-33590
- https://github.com/portainer/portainer/commit/3e2fdb1891e81a8e4c5c8beb60e45f07c8ecae52
- https://github.com/portainer/portainer/commit/ac8fa7672e732b44b970c9eaf928eddd2c68796c
- https://intwave.com/blog/2026/02/26/improving-portainer-security.html
- https://github.com/advisories/GHSA-frhv-529m-5v9v