CVE-2026-44885

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and extracts it to a target directory on the server. The extraction function (ExtractTarGz in api/archive/targz.go) constructed output paths using filepath.Clean(filepath.Join(outputDirPath, header.Name)). This combination does not prevent directory traversal — a tar entry named ../../etc/cron.d/evil resolves to a path outside the extraction root, so a crafted archive can write files to arbitrary locations on the server filesystem. This vulnerability is fixed in 2.33.8.
Configurations

Configuration 1 (hide)

cpe:2.3:a:portainer:portainer:*:*:*:*:community:*:*:*

History

21 Jul 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) Portainer Community Edition es una plataforma ligera de entrega de servicios para aplicaciones en contenedores que puede utilizarse para gestionar entornos Docker, Swarm, Kubernetes y ACI. Desde la versión 2.33.0 hasta antes de la 2.33.8, la función de restauración de copias de seguridad de Portainer acepta un archivo .tar.gz y lo extrae a un directorio de destino en el servidor. La función de extracción (ExtractTarGz en api/archive/targz.go) construía rutas de salida utilizando filepath.Clean(filepath.Join(outputDirPath, header.Name)). Esta combinación no evita el salto de directorio — una entrada tar llamada ../../etc/cron.d/evil se resuelve en una ruta fuera de la raíz de extracción, por lo que un archivo malicioso puede escribir archivos en ubicaciones arbitrarias del sistema de archivos del servidor. Esta vulnerabilidad se corrige en la versión 2.33.8.

01 Jun 2026, 18:08

Type Values Removed Values Added
CPE cpe:2.3:a:portainer:portainer:*:*:*:*:community:*:*:*
First Time Portainer
Portainer portainer
References () https://github.com/portainer/portainer-suite/pull/1875 - () https://github.com/portainer/portainer-suite/pull/1875 - Broken Link
References () https://github.com/portainer/portainer/security/advisories/GHSA-m8fg-67j7-cx4v - () https://github.com/portainer/portainer/security/advisories/GHSA-m8fg-67j7-cx4v - Exploit, Third Party Advisory

28 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 22:16

Updated : 2026-07-21 10:10


NVD link : CVE-2026-44885

Mitre link : CVE-2026-44885

CVE.ORG link : CVE-2026-44885


JSON object : View

Products Affected

portainer

  • portainer
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')