PT-2026-56482 · Portainer+1 · Portainer Community Edition+1
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Portainer Community Edition versions 2.39.0 through 2.39.3
Portainer Community Edition versions 2.40.0 through 2.42.x
Description
Unauthenticated access to specific endpoints is possible during the five-minute setup window of uninitialized instances. A network attacker can exploit this by interacting with the '/api/restore' and '/api/users/admin/init' endpoints to restore a crafted backup or create the initial administrator account, resulting in full administrative access.
Recommendations
Update versions 2.39.0 through 2.39.3 to version 2.39.4.
Update versions 2.40.0 through 2.42.x to version 2.43.0.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Portainer Community Edition
Red Os