PT-2026-56482 · Portainer+1 · Portainer Community Edition+1

·

CVE-2026-55761

·

Published

2026-07-08

·

Updated

2026-09-08

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Portainer Community Edition versions 2.39.0 through 2.39.3 Portainer Community Edition versions 2.40.0 through 2.42.x
Description Unauthenticated access to specific endpoints is possible during the five-minute setup window of uninitialized instances. A network attacker can exploit this by interacting with the '/api/restore' and '/api/users/admin/init' endpoints to restore a crafted backup or create the initial administrator account, resulting in full administrative access.
Recommendations Update versions 2.39.0 through 2.39.3 to version 2.39.4. Update versions 2.40.0 through 2.42.x to version 2.43.0.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55761
GHSA-X626-FCWX-F5PC
GO-2026-6324
OPENSUSE-SU-2026:21812-1

Affected Products

Portainer Community Edition
Red Os