Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent
access on the host.
access on the host.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 28 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host. | |
| Title | Insecure default permissions in Portainer CE | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-05-28T19:30:06.697Z
Reserved: 2026-03-23T12:53:47.474Z
Link: CVE-2026-33590
No data.
Status : Received
Published: 2026-05-28T20:16:23.163
Modified: 2026-05-28T20:16:23.163
Link: CVE-2026-33590
No data.
OpenCVE Enrichment
Updated: 2026-05-28T20:30:25Z
Weaknesses