CVE-2026-44849
Portainer Community Edition had a flaw where restrictions on container configurations were not enforced when using the Docker Swarm service API, allowing privileged containers to be launched. This could let attackers bypass security controls and gain full system access. The issue is fixed in certain newer releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Portainer Community Edition versions 2.33.0 through 2.33.7, 2.39.2, 2.41.0, and 2.40.0. Administrators who manage Docker, Swarm, Kubernetes, or ACI environments with these versions are affected.
Real-world impact
An attacker could create containers with privileged mode, host PID namespace, device mapping, added capabilities, sysctls, security options, or bind mounts, effectively bypassing all administrative restrictions and potentially taking control of the host system.
Why this severity
The CVSS score of 9.4 reflects the vulnerability’s high impact on confidentiality, integrity, and availability, combined with the low effort required to exploit it and the significant privileges an attacker can gain.
What to do about it
- 01Check the current Portainer version.
- 02Upgrade Portainer to a fixed version (2.33.8, 2.39.2, 2.41.0, or later).
NVD-referenced vendor advisory
Timeline
- May 28, 2026 · May 28, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 14d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/portainer/portainer/securit…exploitthird party advisory