Junglewise Threat Intelligence

CVE-2026-44884: Portainer Community Edition missing authorization in custom template endpoint

CVE-2026-44884 · Severity: medium · CVSS 6.5 · Published 2026-05-28

Technologies: Portainer, Portainer Community Edition, github.com/portainer/portainer (Go). Vendors: Portainer, Go.

Executive brief

Portainer is a management tool used to deploy and manage containerized applications. A security flaw allows any logged-in user to view the contents of custom application templates, which often contain sensitive information like database passwords, API keys, or login credentials. This could lead to unauthorized access to other parts of a company's infrastructure if secrets are stored within these templates.

Technical details

A missing authorization check in the `customTemplateFile` handler within `api/http/handler/customtemplates/customtemplate_file.go` allows any authenticated user to access the `GET /api/custom_templates/{id}/file` endpoint. By enumerating sequential integer IDs, an attacker can bypass Resource Control restrictions to retrieve the verbatim file content of any custom template. These templates frequently contain Docker Compose configurations with embedded environment-specific secrets such as connection strings and registry credentials. The vulnerability has been addressed in versions 2.33.8, 2.39.1, and 2.40.0.

Affected products

  • Portainer Portainer >= 2.33.0, < 2.33.8; >= 2.39.0, < 2.39.1

Timeline

  • 2026-02-11: disclosed: Reported via GitHub Security Advisory
  • 2026-03-19: patched: Version 2.39.1 released with fix
  • 2026-03-25: patched: Version 2.40.0 released with fix
  • 2026-05-07: patched: Version 2.33.8 released with fix
  • 2026-05-14: advisory: GHSA-cqpq-2fgr-8mvc published

References

Related threats