Back to search
CVE-2026-33590
Published: May 28, 2026
Modified: May 29, 2026
PUBLISHED
Description
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.
| Vendor | Product | Versions |
|---|---|---|
Portainer | Portainer Community Edition | affected 0 - < 2.39.0affected 0 - < 2.38.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now