Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.
History

Fri, 29 May 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Portainer
Portainer portainer Community Edition
Vendors & Products Portainer
Portainer portainer Community Edition

Fri, 29 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.
Title Insecure default permissions in Portainer CE
Weaknesses CWE-276
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published: 2026-05-28T19:30:06.697Z

Updated: 2026-05-29T14:57:54.101Z

Reserved: 2026-03-23T12:53:47.474Z

Link: CVE-2026-33590

cve-icon Vulnrichment

Updated: 2026-05-29T14:57:49.786Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-28T20:16:23.163

Modified: 2026-05-29T15:06:44.207

Link: CVE-2026-33590

cve-icon Redhat

No data.