Vulnerability Description
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.
Related Weaknesses (CWE)
References
- https://github.com/portainer/portainer/commit/3e2fdb1891e81a8e4c5c8beb60e45f07c8
- https://github.com/portainer/portainer/commit/ac8fa7672e732b44b970c9eaf928eddd2c
- https://intwave.com/blog/2026/02/26/improving-portainer-security.html
- http://www.openwall.com/lists/oss-security/2026/06/12/2
FAQ
What is CVE-2026-33590?
CVE-2026-33590 is a documented vulnerability. Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endp...
How severe is CVE-2026-33590?
CVSS scoring is not yet available for CVE-2026-33590. Check NVD for updates.
Is there a patch for CVE-2026-33590?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.