


Perceptive Security
SOC/SIEM Consultancy

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and A…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 23:02:47
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access
Portainer Community Edition versions 2.33.0 to before 2.33.8 contain an authorization bypass vulnerability in the kubeClientMiddleware component. The middleware fails to properly handle token validation errors due to a missing return statement, allowing unauthorized users to access Kubernetes endpoints. When security.RetrieveTokenData returns an error, execution continues with nil tokenData, bypassing authorization checks. An attacker needs a valid Portainer session to exploit this vulnerability. The flaw affects both Community Edition and Enterprise Edition codebases. The vulnerability is fixed in version 2.33.8.
Technical details
Mitigation steps:
Affected products:
Portainer Community Edition
Portainer Enterprise Edition
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44882
https://github.com/portainer/portainer/security/advisories/GHSA-mgq6-4x29-88r3
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
