Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent
access on the host.
CVSS
No CVSS.
References
Configurations
No configuration.
History
12 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
28 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 20:16
Updated : 2026-06-12 16:16
NVD link : CVE-2026-33590
Mitre link : CVE-2026-33590
CVE.ORG link : CVE-2026-33590
JSON object : View
Products Affected
No product.
CWE
CWE-276
Incorrect Default Permissions
