Executive brief
Portainer is a management platform used to configure and deploy containerized applications. A security flaw allows non-administrative users with access to Docker Swarm environments to bypass safety restrictions and launch containers with unauthorized privileges. This could allow an attacker to gain full control over the underlying host server, potentially leading to data theft or complete service disruption.
Technical details
Portainer fails to validate several EndpointSecuritySettings (including capabilities, sysctls, and security options) when processing Docker Swarm service requests. Specifically, the 'POST /services/create' endpoint uses a partial Go struct that ignores security-sensitive fields, while 'POST /services/{id}/update' lacks security setting validation entirely. Additionally, a flaw in bind-mount detection allows users to bypass restrictions by using volume driver options that emulate bind mounts. An authenticated user with standard access to a Swarm endpoint can exploit these omissions to deploy containers with elevated privileges (e.g., CAP_SYS_ADMIN) or mount the host root filesystem, effectively gaining root access to the Swarm manager. Patches are available in versions 2.33.8, 2.39.2, and 2.41.0.
Affected products
- Portainer Portainer >= 2.33.0, < 2.33.8; >= 2.39.0, < 2.39.2; >= 2.40.0, < 2.41.0
Timeline
- 2026-03-12: disclosed: Private disclosure of volume-driver local-bind variant by route2shell
- 2026-04-05: disclosed: Disclosure of Swarm service bypass by JohannesLks
- 2026-04-18: patched: Fix merged to develop branch
- 2026-04-29: patched: Version 2.41.0 released
- 2026-05-07: patched: LTS versions 2.39.2 and 2.33.8 released
- 2026-05-14: advisory: Public advisory published