CVE 9.4 CRITICAL

Portainer: Endpoint security bypass via Swarm service create/update_CVE-2026-44849

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings restrictions that administrators configure to restrict the container configurations non-admin users can launch: privileged mode, host PID namespace, device mapping, capabilities, sysctls, security-opt (Seccomp / AppArmor), and bind mounts. These restrictions are enforced on the standard container creation path, but several of them are not applied on the Docker Swarm service API. This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0.

AI Analysis

Endpoint security bypass via Swarm service create/update

Basic Information

ID CVE-2026-44849
Source GitHub_M
Published May 28, 2026 at 21:06

Affected Product

Vendor portainer
Product portainer
Version >= 2.33.0, < 2.33.8
Affected Versions portainer portainer >= 2.33.0, < 2.33.8
portainer portainer >= 2.39.0, < 2.39.2
portainer portainer >= 2.40.0, < 2.41.0

CWE Classification

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor Portainer
Product Portainer Community Edition
Version 2.33.0 to 2.33.7, 2.39.0 to 2.39.1, 2.40.0 to 2.40.x

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.