QSearchQSearch

CVE-2026-44849

8.8 HIGH

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, ...

Published: 2026-05-28 · Last updated: 2026-06-01

Severity and scoring

CVSS
8.8 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-862

Affected products

VendorProduct
portainerportainer

Description

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings restrictions that administrators configure to restrict the container configurations non-admin users can launch: privileged mode, host PID namespace, device mapping, capabilities, sysctls, security-opt (Seccomp / AppArmor), and bind mounts. These restrictions are enforced on the standard container creation path, but several of them are not applied on the Docker Swarm service API. This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-44885 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, ... (5.5 MEDIUM)
  • CVE-2026-44884 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, ... (6.5 MEDIUM)
  • CVE-2026-44883 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, ... (7.5 HIGH)
  • CVE-2026-44882 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, ... (8.1 HIGH)
  • CVE-2026-44881 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, ... (9.9 CRITICAL)

Same CWE

  • CVE-2026-12105 Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplicat...
  • CVE-2026-53866 OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators ... (8.1 HIGH)
  • CVE-2026-53851 OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite... (5.3 MEDIUM)
  • CVE-2026-53850 OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated caller... (5.5 MEDIUM)
  • CVE-2026-53844 OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated call... (6.5 MEDIUM)