Vendor CVEs
Portainer
All CVEs
29 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24264 | Cri | 0.64 | 9.8 | 0.04 | Mar 16, 2021 | Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a container with bind mount. Once… | ||
| CVE-2018-19367 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2018 | Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created. This API endpoint will return 404 if admin was not created and 204 if it was already created. Attackers can set an admin password in the 404 case. | ||
| CVE-2026-72533 | Hig | 0.57 | 8.8 | 0.00 | Aug 11, 2026 | An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request… | ||
| CVE-2026-44881 | Cri | 0.57 | 9.9 | 0.00 | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer supports deploying stacks from Git… | ||
| CVE-2020-24263 | Hig | 0.57 | 8.8 | 0.02 | Mar 16, 2021 | Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host. | ||
| CVE-2019-16872 | Cri | 0.57 | 9.9 | 0.01 | Nov 7, 2019 | Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4). | ||
| CVE-2026-44849 | Hig | 0.50 | 8.8 | 0.00 | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings… | ||
| CVE-2026-44848 | Hig | 0.50 | 8.8 | 0.00 | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, The Docker plugin management endpoints (/plugins/*)… | ||
| CVE-2019-16877 | Hig | 0.50 | 8.8 | 0.01 | Nov 7, 2019 | Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4). | ||
| CVE-2024-33662 | Hig | 0.49 | 7.5 | 0.00 | Oct 2, 2024 | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. | ||
| CVE-2026-44850 | Hig | 0.48 | 8.5 | 0.00 | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an environment-level Disable bind… | ||
| CVE-2026-33590 | Hig | 0.48 | — | 0.00 | May 28, 2026 | Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root… | ||
| CVE-2026-44882 | Hig | 0.46 | 8.1 | 0.00 | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33., Portainer proxies requests to Kubernetes clusters through a middleware… | ||
| CVE-2026-44883 | Hig | 0.42 | 7.5 | 0.00 | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer's authentication middleware accepts JWT… | ||
| CVE-2019-16876 | Hig | 0.42 | 7.5 | 0.01 | Nov 7, 2019 | Portainer before 1.22.1 allows Directory Traversal. | ||
| CVE-2025-49593 | Med | 0.37 | 6.8 | 0.00 | Jun 17, 2025 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to… | ||
| CVE-2026-44884 | Med | 0.35 | 6.5 | 0.00 | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a missing authorization vulnerability in the Custom Template… | ||
| CVE-2024-29296 | Med | 0.35 | 5.3 | 0.01 | Apr 10, 2024 | A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. | ||
| CVE-2019-16878 | Med | 0.35 | 5.4 | 0.01 | Nov 7, 2019 | Portainer before 1.22.1 has XSS (issue 2 of 2). | ||
| CVE-2019-16874 | Med | 0.35 | 6.5 | 0.01 | Nov 7, 2019 | Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4). | ||
| CVE-2026-44885 | Med | 0.29 | 5.5 | 0.01 | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and… | ||
| CVE-2019-16873 | Med | 0.28 | 5.4 | 0.01 | Nov 7, 2019 | Portainer before 1.22.1 has XSS (issue 1 of 2). | ||
| CVE-2026-55761 | Med | 0.00 | 5.9 | 0.00 | Jul 8, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator… | ||
| CVE-2024-33661 | Cri | 0.00 | 9.1 | 0.01 | Apr 26, 2024 | Portainer before 2.20.0 allows redirects when the target is not index.yaml. | ||
| CVE-2022-24961 | Cri | 0.00 | 9.8 | 0.02 | Feb 11, 2022 | In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days. | ||
| CVE-2021-42650 | Med | 0.00 | 6.1 | 0.01 | Oct 18, 2021 | Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates. | ||
| CVE-2018-19466 | Cri | 0.00 | 9.8 | 0.04 | Mar 27, 2019 | A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls. | ||
| CVE-2018-16316 | Med | 0.00 | 5.4 | 0.01 | Sep 1, 2018 | A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field. | ||
| CVE-2018-12678 | Cri | 0.00 | 9.8 | 0.02 | Jun 22, 2018 | Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access restrictions or conduct SSRF attacks. |
- risk 0.64cvss 9.8epss 0.04
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a container with bind mount. Once…
- risk 0.64cvss 9.8epss 0.01
Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created. This API endpoint will return 404 if admin was not created and 204 if it was already created. Attackers can set an admin password in the 404 case.
- risk 0.57cvss 8.8epss 0.00
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request…
- risk 0.57cvss 9.9epss 0.00
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer supports deploying stacks from Git…
- risk 0.57cvss 8.8epss 0.02
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.
- risk 0.57cvss 9.9epss 0.01
Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).
- risk 0.50cvss 8.8epss 0.00
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings…
- risk 0.50cvss 8.8epss 0.00
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, The Docker plugin management endpoints (/plugins/*)…
- risk 0.50cvss 8.8epss 0.01
Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
- risk 0.49cvss 7.5epss 0.00
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
- risk 0.48cvss 8.5epss 0.00
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an environment-level Disable bind…
- risk 0.48cvss —epss 0.00
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root…
- risk 0.46cvss 8.1epss 0.00
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33., Portainer proxies requests to Kubernetes clusters through a middleware…
- risk 0.42cvss 7.5epss 0.00
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer's authentication middleware accepts JWT…
- risk 0.42cvss 7.5epss 0.01
Portainer before 1.22.1 allows Directory Traversal.
- risk 0.37cvss 6.8epss 0.00
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to…
- risk 0.35cvss 6.5epss 0.00
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a missing authorization vulnerability in the Custom Template…
- risk 0.35cvss 5.3epss 0.01
A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.
- risk 0.35cvss 5.4epss 0.01
Portainer before 1.22.1 has XSS (issue 2 of 2).
- risk 0.35cvss 6.5epss 0.01
Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).
- risk 0.29cvss 5.5epss 0.01
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and…
- risk 0.28cvss 5.4epss 0.01
Portainer before 1.22.1 has XSS (issue 1 of 2).
- risk 0.00cvss 5.9epss 0.00
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator…
- risk 0.00cvss 9.1epss 0.01
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
- risk 0.00cvss 9.8epss 0.02
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.
- risk 0.00cvss 6.1epss 0.01
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
- risk 0.00cvss 9.8epss 0.04
A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls.
- risk 0.00cvss 5.4epss 0.01
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.
- risk 0.00cvss 9.8epss 0.02
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access restrictions or conduct SSRF attacks.