ZeroHour

Vulnerabilities

26 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-55761
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and A

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access. This issue is fixed in versions 2.39.4 and 2.43.0.

NVD description · AI analysis pending
7.1<1% PoC
  • portainer portainer
CVE-2026-44848
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and A

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, The Docker plugin management endpoints (/plugins/*) were not registered with a handler, so standard users with endpoint access could call privileged plugin operations — including installing and enabling plugins — directly against the underlying Docker daemon. The vulnerability is exposed when a non-admin Portainer user (Standard User role, or any role granted endpoint-level access) has been given access to a Docker endpoint via Portainer RBAC. This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0.

NVD description · AI analysis pending
9.4
group max
<1% PoC
  • portainer portainer
CVE-2024-33662
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

NVD description · AI analysis pending
7.5<1%
  • portainer portainer
CVE-2024-33661
Portainer before 2.20.0 allows redirects when the target is not index.yaml.

Portainer before 2.20.0 allows redirects when the target is not index.yaml.

NVD description · AI analysis pending
9.1<1%
  • portainer portainer
CVE-2024-29296
A user enumeration vulnerability was found in Portainer CE 2.19.4.

A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.

NVD description · AI analysis pending
5.31% PoC
  • portainer portainer
CVE-2022-24961
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

NVD description · AI analysis pending
9.82%
  • portainer portainer
CVE-2021-42650
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.

Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.

NVD description · AI analysis pending
6.1<1%
  • portainer portainer
CVE-2020-24264
+1 in the same advisory: …24263
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution.

Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a container with bind mount. Once such a container is spawned, it can be leveraged to break out of the container leading to complete Docker host machine takeover.

NVD description · AI analysis pending
9.8
group max
4%
  • portainer portainer
CVE-2019-16872
Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).

Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).

NVD description · AI analysis pending
9.9
group max
1%
  • portainer portainer
CVE-2018-19466
A vulnerability was found in Portainer before 1.20.0.

A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls.

NVD description · AI analysis pending
9.84% PoC
  • portainer portainer
CVE-2018-19367
Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created.

Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created. This API endpoint will return 404 if admin was not created and 204 if it was already created. Attackers can set an admin password in the 404 case.

NVD description · AI analysis pending
9.81% PoC ×2
  • portainer portainer
CVE-2018-16316
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via t

A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.

NVD description · AI analysis pending
5.4<1%
  • portainer portainer
CVE-2018-12678
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, whi

Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access restrictions or conduct SSRF attacks.

NVD description · AI analysis pending
9.82%
  • portainer portainer