CVE-2026-44848 Details
Description
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, The Docker plugin management endpoints (/plugins/*) were not registered with a handler, so standard users with endpoint access could call privileged plugin operations — including installing and enabling plugins — directly against the underlying Docker daemon. The vulnerability is exposed when a non-admin Portainer user (Standard User role, or any role granted endpoint-level access) has been given access to a Docker endpoint via Portainer RBAC. This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0.
A critical vulnerability exists in Portainer Community Edition versions 2.33.0 prior to 2.33.8, 2.39.0 prior to 2.39.2, and 2.40.0 prior to 2.41.0. The issue arises from Docker plugin management endpoints not being properly registered with an authorization handler. As a result, standard users with endpoint access could perform privileged plugin operations, such as installing and enabling plugins, directly on the Docker daemon. This vulnerability is particularly concerning because it allows non-admin users to execute code with root privileges on the Docker host, accessing the host filesystem and effectively gaining root access on the Docker host.
Users can upgrade to Portainer versions 2.33.8, 2.39.2, or 2.41.0 to address this vulnerability. For those unable to upgrade immediately, Docker endpoint access for non-admin users can be revoked via Portainer RBAC as a temporary measure.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/portainer/portainer/security/advisories/GHSA-rrmm-9v76-h3p4 | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/portainer/portainer/security/advisories/GHSA-rrmm-9v76-h3p4 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| portainer portainer | >= 2.33.0, < 2.33.8 >= 2.34.0, < 2.39.2 2.40.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | [email protected] |