CVE-2026-33590 Details
Description
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.
A vulnerability in Portainer Community Edition (CE) prior to version 2.38.0 allows regular (non-admin) users to access the host filesystem and execute code at the host level. This issue arises from insecure default security settings that grant excessive privileges to non-administrative users with endpoint access. Exploitation of this vulnerability enables the reading of host files or obtaining root-equivalent access on the host.
Users are advised to upgrade to Portainer versions 2.38.0 or 2.39.0, where the default security settings for regular users have been significantly tightened. After upgrading, it is recommended to review the Docker Security Settings to ensure they align with the desired security posture.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | ENISA |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ENISA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | CVE Modified | CVE |
| May 28, 2026 | New CVE Received | ENISA |