Junglewise Threat Intelligence

CVE-2026-44850: Portainer Community Edition authorization bypass in bind-mount restriction

CVE-2026-44850 · Severity: high · CVSS 8.5 · Published 2026-05-28

Technologies: Portainer, Portainer Community Edition, github.com/portainer/portainer (Go). Vendors: Portainer, Go.

Executive brief

Portainer is a management platform used to run and monitor containerized applications like Docker and Kubernetes. A security flaw allowed standard users to bypass restrictions intended to prevent them from accessing the underlying server's file system. By exploiting this, an authorized user could gain full access to sensitive files on the host server, potentially leading to a total compromise of the infrastructure and all other applications running on it.

Technical details

An authorization bypass exists in Portainer's container-create proxy due to incomplete inspection of the Docker API request body. While Portainer offers a 'Disable bind mounts for non-administrators' setting, the enforcement logic in 'decorateContainerCreationOperation' only validated the legacy 'HostConfig.Binds' array and failed to check the 'HostConfig.Mounts' array. An authenticated user with container-creation privileges can use the 'Mounts' field to perform bind mounts of any host path. This allows the attacker to read or write sensitive host files (such as SSH keys or the Docker socket) with the privileges of the Docker daemon, typically root. The issue is resolved in versions 2.33.8, 2.39.2, and 2.41.0.

Affected products

  • Portainer Portainer Community Edition 2.33.0 to < 2.33.8, 2.39.0 to < 2.39.2, 2.40.0 to < 2.41.0

Timeline

  • 2026-05-10: advisory: GitHub advisory published by Portainer
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats