Critical Portainer Flaws Grant Restricted Users Root Access to the Host
ID: 833ea4ee-7577-55fa-911d-60fcfd30936f
STIX ID: report--833ea4ee-7577-55fa-911d-60fcfd30936f
Feed Name: securityonline.info
Two critical Portainer CE vulnerabilities (CVE-2026-44848 and CVE-2026-44849, CVSS 9.4) let authenticated non-admin users bypass RBAC and host isolation: unprotected /plugins/* endpoints allow malicious Docker plugins to be pulled and enabled as host-root, and insufficient validation of Swarm service create/update APIs permits injection of privileged capabilities, host bind mounts, or disabling of security filters. Fixed releases have been backported across supported branches; admins are advised to revoke endpoint access for non-admins, isolate manager nodes, and enforce daemon-side volume allowlists as temporary mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
