9.4
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings restrictions that administrators configure to restrict the container configurations non-admin users can launch: privileged mode, host PID namespace, device mapping, capabilities, sysctls, security-opt (Seccomp / AppArmor), and bind mounts. These restrictions are enforced on the standard container creation path, but several of them are not applied on the Docker Swarm service API. This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0.
AI Analysis
Endpoint security bypass via Swarm service create/update
Basic Information
ID
CVE-2026-44849
Source
GitHub_M
Published
May 28, 2026 at 21:06
Affected Product
Vendor
portainer
Product
portainer
Version
>= 2.33.0, < 2.33.8
Affected Versions
portainer portainer >= 2.33.0, < 2.33.8
portainer portainer >= 2.39.0, < 2.39.2
portainer portainer >= 2.40.0, < 2.41.0
portainer portainer >= 2.39.0, < 2.39.2
portainer portainer >= 2.40.0, < 2.41.0
CWE Classification
AI Assessment
AI Score
9.4 / 10
AI Severity
Critical
Vendor
Portainer
Product
Portainer Community Edition
Version
2.33.0 to 2.33.7, 2.39.0 to 2.39.1, 2.40.0 to 2.40.x