CVE-2026-33590: Portainer Community Edition
High severity, CVSS 8.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.
Affected products
- Portainer Portainer Community Edition: before 2.39.0 (fixed in 2.39.0); before 2.38.0 (fixed in 2.38.0)
Published 2026-05-28. Last modified 2026-06-17.