Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

portainer — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting portainer. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the vendor Portainer, focusing on specific weakness types and relevant tags. It collects reported flaws within the Portainer product ecosystem, covering a defined historical time range to provide a comprehensive view of past security incidents. Readers can use this resource to track the vendor's published advisories, understand specific weakness classes affecting their infrastructure, or look up the complete vulnerability history for a particular Portainer release. The data is organized to facilitate technical analysis, allowing security professionals and developers to identify recurring patterns in software defects. By centralizing these records, the page supports risk assessment and patch management strategies for organizations deploying container management solutions. The entries reflect verified security issues, ranging from authentication bypasses to remote code execution risks, ensuring that stakeholders have access to accurate information regarding the security posture of Portainer products. This aggregation helps in understanding how vulnerabilities have evolved over time and which components are most frequently targeted by attackers.

CVE ID Title CVSS Severity Published
CVE-2026-72533 Portainer Portainer CE - Authentication Bypass — Portainer CE CWE-287 8.8 High 2026-08-11
CVE-2026-55761 Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances — portainer CWE-287 - - 2026-07-08
CVE-2026-44881 Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update — portainer CWE-59 - - 2026-05-28
CVE-2026-44848 Portainer: Missing authorization on Docker plugin endpoints allows host RCE — portainer CWE-862 - - 2026-05-28
CVE-2026-44849 Portainer: Endpoint security bypass via Swarm service create/update — portainer CWE-862 - - 2026-05-28
CVE-2026-44850 Portainer: Bind-mount restriction bypass via HostConfig.Mounts — portainer CWE-863 8.5 High 2026-05-28
CVE-2026-44882 Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization — portainer CWE-863 8.1 High 2026-05-28
CVE-2026-44883 Portainer: JWT accepted in URL query leaks tokens to logs and referers — portainer CWE-598 - - 2026-05-28
CVE-2026-44884 Portainer: Missing authorization on custom template file endpoint exposes template content — portainer CWE-862 - - 2026-05-28
CVE-2026-44885 Portainer: Path traversal in backup archive extraction allows arbitrary file write — portainer CWE-22 5.5 Medium 2026-05-28
CVE-2026-33590 Insecure default permissions in Portainer CE — Portainer Community Edition CWE-276 - - 2026-05-28
CVE-2025-49593 Portainer HTTP Headers May Leak to Malicious Container Registries — portainer CWE-200 6.8 Medium 2025-06-17

This page lists every published CVE security advisory associated with portainer. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.