PT-2026-70108 · Portainer · Portainer Ce

·

CVE-2026-72533

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Portainer CE versions prior to 2.44.1
Description An authentication bypass occurs when authenticated low-privileged users bypass Docker proxy authorization checks. This is caused by non-canonical URL normalization, where the proxy endpoint fails to normalize request paths before applying access controls. This discrepancy allows crafted requests to be interpreted differently by the proxy and the authorization layer, defeating all authorization middleware and granting the attacker root-level access to the underlying Docker host.
Recommendations Update Portainer CE to version 2.44.1 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72533

Affected Products

Portainer Ce