CVE-2026-44881 | portainer Community Edition up to 2.33.7/2.39.1/2.40.x /api/stacks/{id}/file link following (GHSA-rpgq-m5fp-32wr)
ID: d2655c6f-4fa6-57a5-8193-e995df87d779
STIX ID: report--d2655c6f-4fa6-57a5-8193-e995df87d779
Feed Name: VulDB Recent Entries
Threat Score
Portainer Community Edition is affected by a link-following vulnerability (CVE-2026-44881) in the /api/stacks/{id}/file endpoint that allows authenticated users with rights to create or update Git-backed stacks to read arbitrary files by exploiting symlinked repository entries; technical details are published, no exploit is available, and the issue is fixed in Portainer CE 2.33.8, 2.39.2 and 2.41.0 — upgrade is recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
