PT-2026-70108 · Portainer · Portainer Ce
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Portainer CE versions prior to 2.44.1
Description
An authentication bypass occurs when authenticated low-privileged users bypass Docker proxy authorization checks. This is caused by non-canonical URL normalization, where the proxy endpoint fails to normalize request paths before applying access controls. This discrepancy allows crafted requests to be interpreted differently by the proxy and the authorization layer, defeating all authorization middleware and granting the attacker root-level access to the underlying Docker host.
Recommendations
Update Portainer CE to version 2.44.1 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Portainer Ce