CVE-2020-24263: Portainer

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.

Affected products

  • Portainer Portainer: up to and including 1.24.1

Published 2021-03-16. Last modified 2026-06-17.