CVE-2026-44848Patch(portainer / portainer)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch portainer portainer systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, The Docker plugin management endpoints (/plugins/*) were not registered with a handler, so standard users with endpoint access could call privileged plugin operations — including installing and enabling plugins — directly against the underlying Docker daemon. The vulnerability is exposed when a non-admin Portainer user (Standard User role, or any role granted endpoint-level access) has been given access to a Docker endpoint via Portainer RBAC. This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • portainer

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-14); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
portainer

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-14: 1Mentions · 2026-05-19: 1Mentions · 2026-05-20: 1Mentions · 2026-06-17: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 105-1405-1905-2006-17
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-141
Patch1
2026-05-191
Patch1
2026-05-201
Patch1
2026-06-171
Disclosure1
Full discourse4 posts
  • Henrique Pereira@ikkebr
    Disclosure

    Earlier this year I set a goal to end the year with a couple CVEs to my name. So far, the year is going great: - CVE-2026-48579 (9.1 on MS Exchange) - CVE-2026-33102 (9.3 on M365 Copilot) - CVE-2026-21532 (8.2 on Azure Functions) - CVE-2026-44848 (9.4 on Portainer) - CVE-2026-55092 (8.0 on Trivy) Plus a plethora of other vulns I reported and got fixed without CVEs…

    Post summary

    The author announces having discovered and named five CVEs, listing their severity scores and affected products, without providing exploit details or mitigation information.

    0202242.0K
    965 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Portainer fixes two critical 9.4 CVSS flaws (CVE-2026-44848/49) allowing instant container escape to host root. Patch your environments now! #Portainer #Docker #ContainerSecurity #InfoSec #CyberSecurity #VulnerabilityAlert #CVE https://securityonline.info/portainer-container-escape-vulnerabilities-cve-2026-44848-cve-2026-44849/ https://t.co/E7t95SseYI

    Post summary

    The post announces that Portainer has fixed two critical CVEs that enable container escape and urges readers to apply the patch immediately.

    02082503
    12.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Portainer Endpoint Security Bypass via Docker Swarm Service (CVE-2026-44849), (CVE-2026-44848) Portainer fails to enforce EndpointSecuritySettings restrictions (capabilities, sysctls, security-opt, bind mounts, etc.) on Docker Swarm service create and update endpoints. A non-admin user with access to a Swarm endpoint can bypass these controls to add full capabilities (SYS_ADMIN, ALL), unconfined Seccomp/AppArmor, arbitrary sysctls, and host filesystem bind mounts. This allows privilege escalation and full host compromise from a restricted account. 👉Affected: Portainer >=2.33.0 <2.33.8, >=2.39.0 <2.39.2, >=2.40.0 <2.41.0 | Upgrade to 2.33.8 2.39.2 2.41.0

    Post summary

    Portainer versions 2.33.x, 2.39.x, and 2.40.x contain a critical endpoint‑security bypass that allows non‑admin users to gain root‑level access; users should immediately upgrade to the patched releases to mitigate the risk.

    00021168
    255 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Two Critical vulnerabilities in #Portainer (CVSS 9.4) allow authenticated non-admin users to gain full root-level #RCE on the Docker host. #CVE-2026-44848 via unguarded plugin endpoints; #CVE-2026-44849 via Swarm security bypass. #Patch #Patch #Patch

    Post summary

    The post warns of two critical CVEs in Portainer that allow authentication bypass and RCE; it emphasizes that patches are available.

    00000241
    7.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appportainerportainer---
Appportainerportainer2.40.0--

Explore more