8.5
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
Description
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent
access on the host.
access on the host.
AI Analysis
Insecure default settings grant non-admin users host filesystem access and code execution privileges
Basic Information
ID
CVE-2026-33590
Source
ENISA
Published
May 28, 2026 at 19:30
Affected Product
Vendor
Portainer
Product
Portainer Community Edition
Affected Versions
Portainer Portainer Community Edition 0
Portainer Portainer Community Edition 0
Portainer Portainer Community Edition 0
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
Portainer
Product
Portainer Community Edition