CVE-2026-44848
A flaw in Portainer Community Edition let regular users run privileged Docker plugin actions. The bug existed in several older releases and was fixed in newer ones. Users with endpoint access could install or enable plugins on the Docker host without admin rights.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Portainer Community Edition versions 2.33.0 through 2.33.7, 2.39.1, and earlier than 2.39.2 are affected. The 2.40.0 release is not impacted.
Real-world impact
An attacker who gains a standard user account in Portainer can install malicious Docker plugins or enable existing ones, giving them full control over the Docker daemon and the host system.
Why this severity
The CVSS score of 9.4 reflects the high impact of the vulnerability: it allows attackers to gain full control over the Docker host (high confidentiality, integrity, and availability impact) with low effort and no authentication beyond a standard user role.
What to do about it
- 01Upgrade Portainer to a fixed version (2.33.8 or later, 2.39.2 or later, or 2.41.0 or later).
- 02Verify the upgrade by checking the version number in the Portainer UI or via the API.
- 03Restart the Portainer service to ensure the new version is running.
- 04Confirm that no older, vulnerable versions remain on the system.
NVD-referenced vendor advisory
Timeline
- May 28, 2026 · May 28, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 14d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/portainer/portainer/securit…exploitthird party advisory