logo

CVE-2026-44881 | portainer Community Edition up to 2.33.7/2.39.1/2.40.x /api/stacks/{id}/file link following (GHSA-rpgq-m5fp-32wr)

ID: d2655c6f-4fa6-57a5-8193-e995df87d779

STIX ID: report--d2655c6f-4fa6-57a5-8193-e995df87d779

Feed Name: VulDB Recent Entries

Threat Score
55/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: vuldb.com

...
...

Portainer Community Edition is affected by a link-following vulnerability (CVE-2026-44881) in the /api/stacks/{id}/file endpoint that allows authenticated users with rights to create or update Git-backed stacks to read arbitrary files by exploiting symlinked repository entries; technical details are published, no exploit is available, and the issue is fixed in Portainer CE 2.33.8, 2.39.2 and 2.41.0 — upgrade is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.