CVE-2026-33590

Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.
CVSS

No CVSS.

Configurations

No configuration.

History

12 Jun 2026, 16:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/06/12/2 -

28 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 20:16

Updated : 2026-06-12 16:16


NVD link : CVE-2026-33590

Mitre link : CVE-2026-33590

CVE.ORG link : CVE-2026-33590


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions