Portainer
Portainer: vulnerabilidades y CVE
Portainer tiene 26 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses9
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55761 | Alta (7.1) | 0.49% | — | 8 jul 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and… |
| CVE-2026-44885 | Media (5.5) | 0.80% | — | 28 may 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's… |
| CVE-2026-44884 | Media (6) | 0.38% | — | 28 may 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a… |
| CVE-2026-44883 | Alta (7.7) | 0.46% | — | 28 may 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and… |
| CVE-2026-44882 | Alta (8.1) | 0.48% | — | 28 may 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33., Portainer… |
| CVE-2026-44881 | Alta (8.5) | 0.58% | — | 28 may 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and… |
| CVE-2026-44850 | Alta (8.5) | 0.30% | — | 28 may 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and… |
| CVE-2026-44849 | Crítica (9.4) | 0.45% | — | 28 may 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and… |
| CVE-2026-44848 | Crítica (9.4) | 0.45% | — | 28 may 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and… |
| CVE-2024-33662 | Alta (7.5) | 0.28% | — | 2 oct 2024 | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. |
| CVE-2024-33661 | Crítica (9.1) | 0.62% | — | 26 abr 2024 | Portainer before 2.20.0 allows redirects when the target is not index.yaml. |
| CVE-2024-29296 | Media (5.3) | 1.3% | — | 10 abr 2024 | A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a… |
| CVE-2022-24961 | Crítica (9.8) | 1.6% | — | 11 feb 2022 | In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days. |
| CVE-2021-42650 | Media (6.1) | 0.63% | — | 18 oct 2021 | Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates. |
| CVE-2020-24264 | Crítica (9.8) | 4.1% | — | 16 mar 2021 | Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side,… |
| CVE-2020-24263 | Alta (8.8) | 1.6% | — | 16 mar 2021 | Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as… |
| CVE-2019-16878 | Media (5.4) | 0.52% | — | 7 nov 2019 | Portainer before 1.22.1 has XSS (issue 2 of 2). |
| CVE-2019-16877 | Alta (8.8) | 1.0% | — | 7 nov 2019 | Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4). |
| CVE-2019-16876 | Alta (7.5) | 1.4% | — | 7 nov 2019 | Portainer before 1.22.1 allows Directory Traversal. |
| CVE-2019-16872 | Crítica (9.9) | 1.4% | — | 7 nov 2019 | Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4). |
| CVE-2019-16874 | Media (6.5) | 0.89% | — | 7 nov 2019 | Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4). |
| CVE-2019-16873 | Media (5.4) | 0.52% | — | 7 nov 2019 | Portainer before 1.22.1 has XSS (issue 1 of 2). |
| CVE-2018-19466 | Crítica (9.8) | 3.7% | — | 27 mar 2019 | A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls. |
| CVE-2018-19367 | Crítica (9.8) | 1.5% | — | 20 nov 2018 | Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created. This API endpoint will return 404 if admin was not created and 204 if it was already created.… |
| CVE-2018-16316 | Media (5.4) | 0.79% | — | 1 sept 2018 | A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field. |
| CVE-2018-12678 | Crítica (9.8) | 2.3% | — | 22 jun 2018 | Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.