Executive brief
Portainer CE, a popular tool for managing containerized applications, contained insecure default settings that granted excessive permissions to non-administrative users. An authenticated user could exploit these settings to access sensitive files on the host server or gain full administrative control (root access) over the underlying host. This could lead to a complete system takeover, data theft, or disruption of all services running on the affected server.
Technical details
Portainer CE versions prior to 2.38.0 shipped with insecure default 'Endpoint Security' settings (CWE-276). Specifically, the default configuration enabled 'allowBindMountsForRegularUsers', 'allowPrivilegedModeForRegularUsers', and 'allowHostNamespaceForRegularUsers' for non-administrative accounts. An authenticated attacker with regular user access to an endpoint can exploit these settings to mount the host's root filesystem into a container or run containers in privileged mode to escape the container environment. This facilitates host-level file disclosure (e.g., reading /etc/shadow) and arbitrary code execution with root capabilities on the host system. The issue was addressed by changing these defaults to 'false' in Portainer CE 2.38.0 (STS) and 2.39.0 (LTS).
Affected products
- Portainer Portainer CE < 2.38.0
Timeline
- 2025-11: other: Vulnerability discovered during research internship
- 2026-02-26: disclosed: Technical blog post published by researcher
- 2026-05-28: advisory: CVE published to NVD