CVE-2026-44849Patch(portainer / portainer)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch portainer portainer systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings restrictions that administrators configure to restrict the container configurations non-admin users can launch: privileged mode, host PID namespace, device mapping, capabilities, sysctls, security-opt (Seccomp / AppArmor), and bind mounts. These restrictions are enforced on the standard container creation path, but several of them are not applied on the Docker Swarm service API. This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • portainer

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-14); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
portainer

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-14: 1Mentions · 2026-05-19: 1Mentions · 2026-05-20: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 105-1405-1905-20
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-141
Disclosure1
2026-05-191
Patch1
2026-05-201
Patch1
Full discourse3 posts
  • Gray Hats@the_yellow_fall
    Patch

    Portainer fixes two critical 9.4 CVSS flaws (CVE-2026-44848/49) allowing instant container escape to host root. Patch your environments now! #Portainer #Docker #ContainerSecurity #InfoSec #CyberSecurity #VulnerabilityAlert #CVE https://securityonline.info/portainer-container-escape-vulnerabilities-cve-2026-44848-cve-2026-44849/ https://t.co/E7t95SseYI

    Post summary

    The post announces that Portainer has released a patch fixing two critical container escape flaws (CVE-2026-44848/49) and urges users to apply the update.

    02082503
    12.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Portainer Endpoint Security Bypass via Docker Swarm Service (CVE-2026-44849), (CVE-2026-44848) Portainer fails to enforce EndpointSecuritySettings restrictions (capabilities, sysctls, security-opt, bind mounts, etc.) on Docker Swarm service create and update endpoints. A non-admin user with access to a Swarm endpoint can bypass these controls to add full capabilities (SYS_ADMIN, ALL), unconfined Seccomp/AppArmor, arbitrary sysctls, and host filesystem bind mounts. This allows privilege escalation and full host compromise from a restricted account. 👉Affected: Portainer >=2.33.0 <2.33.8, >=2.39.0 <2.39.2, >=2.40.0 <2.41.0 | Upgrade to 2.33.8 2.39.2 2.41.0

    Post summary

    The post discloses new critical CVEs in Portainer that allow privilege escalation via Docker Swarm services, details the technical fail, and recommends version upgrades as remediation.

    00021168
    255 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Two Critical vulnerabilities in #Portainer (CVSS 9.4) allow authenticated non-admin users to gain full root-level #RCE on the Docker host. #CVE-2026-44848 via unguarded plugin endpoints; #CVE-2026-44849 via Swarm security bypass. #Patch #Patch #Patch

    Post summary

    Two critical CVEs in Portainer allow authenticated non-admin users to achieve root-level RCE; patches are urgently required.

    00000241
    7.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appportainerportainer---
Appportainerportainer2.40.0--

Explore more