Executive brief
Portainer is a management tool used to simplify the deployment and monitoring of Docker containers. A security flaw allows non-administrator users with access to a Docker environment to bypass security checks and install malicious plugins. This can lead to a complete takeover of the underlying server, allowing attackers to access sensitive files and execute commands with root privileges.
Technical details
A missing authorization vulnerability exists in Portainer's Docker API proxy layer. The proxy uses a prefix-based allowlist to route requests to handlers that enforce Role-Based Access Control (RBAC); however, the '/plugins' prefix was omitted from this map. Consequently, requests to plugin management endpoints fall through to a default execution function that forwards them to the Docker daemon without any authorization checks. An authenticated user with standard access to a Docker endpoint can pull, install, and enable arbitrary Docker plugins. Because Docker plugins can be configured with 'CAP_SYS_ADMIN' privileges and host-path mounts, an attacker can achieve full remote code execution and filesystem access as root on the host machine.
Affected products
- Portainer Portainer >= 2.33.0, < 2.33.8; >= 2.39.0, < 2.39.2; >= 2.40.0, < 2.41.0
Timeline
- 2026-03-16: disclosed: Reported by Henrique Pereira (ikkebr) via GitHub Security Advisory
- 2026-04-20: patched: Fix merged to development and release branches
- 2026-04-29: advisory: Version 2.41.0 released
- 2026-05-07: advisory: Versions 2.39.2-LTS and 2.33.8-LTS released