top of page
perceptive_background_267k.jpg

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and A…

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 23:02:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Security Tools

Portainer Community Edition versions 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0 contain a security bypass vulnerability. The 'Disable bind mounts for non-administrators' setting can be circumvented by authenticated users. The vulnerability occurs because the security check only inspects the legacy HostConfig.Binds array but ignores the equivalent HostConfig.Mounts array. Attackers can submit bind-typed entries under HostConfig.Mounts to mount any host path into their containers. This allows unauthorized access to host filesystem resources that should be restricted to administrators only.

Technical details

Mitigation steps:

Affected products:

Portainer Community Edition

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page