CVE-2020-24263: Portainer
High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.
Affected products
- Portainer Portainer: up to and including 1.24.1
Published 2021-03-16. Last modified 2026-06-17.