« Volver al listado

Portainer

Portainer: vulnerabilidades y CVE

Portainer tiene 26 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE26
Últimos 12 meses9
Críticas9
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-55761Alta (7.1)0.49%—8 jul 2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and…
CVE-2026-44885Media (5.5)0.80%—28 may 2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's…
CVE-2026-44884Media (6)0.38%—28 may 2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a…
CVE-2026-44883Alta (7.7)0.46%—28 may 2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and…
CVE-2026-44882Alta (8.1)0.48%—28 may 2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33., Portainer…
CVE-2026-44881Alta (8.5)0.58%—28 may 2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and…
CVE-2026-44850Alta (8.5)0.30%—28 may 2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and…
CVE-2026-44849Crítica (9.4)0.45%—28 may 2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and…
CVE-2026-44848Crítica (9.4)0.45%—28 may 2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and…
CVE-2024-33662Alta (7.5)0.28%—2 oct 2024
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
CVE-2024-33661Crítica (9.1)0.62%—26 abr 2024
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
CVE-2024-29296Media (5.3)1.3%—10 abr 2024
A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a…
CVE-2022-24961Crítica (9.8)1.6%—11 feb 2022
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.
CVE-2021-42650Media (6.1)0.63%—18 oct 2021
Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
CVE-2020-24264Crítica (9.8)4.1%—16 mar 2021
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side,…
CVE-2020-24263Alta (8.8)1.6%—16 mar 2021
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as…
CVE-2019-16878Media (5.4)0.52%—7 nov 2019
Portainer before 1.22.1 has XSS (issue 2 of 2).
CVE-2019-16877Alta (8.8)1.0%—7 nov 2019
Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
CVE-2019-16876Alta (7.5)1.4%—7 nov 2019
Portainer before 1.22.1 allows Directory Traversal.
CVE-2019-16872Crítica (9.9)1.4%—7 nov 2019
Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).
CVE-2019-16874Media (6.5)0.89%—7 nov 2019
Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4).
CVE-2019-16873Media (5.4)0.52%—7 nov 2019
Portainer before 1.22.1 has XSS (issue 1 of 2).
CVE-2018-19466Crítica (9.8)3.7%—27 mar 2019
A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls.
CVE-2018-19367Crítica (9.8)1.5%—20 nov 2018
Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created. This API endpoint will return 404 if admin was not created and 204 if it was already created.…
CVE-2018-16316Media (5.4)0.79%—1 sept 2018
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.
CVE-2018-12678Crítica (9.8)2.3%—22 jun 2018
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1078 Valid Accounts3
  3. T1005 Data from Local System1
  4. T1068 Exploitation for Privilege Escalation1
  5. T1078.002 Domain Accounts1
  6. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Portainer