CVE-2026-44850
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an environment-level Disable bind mounts for non-administrators security setting that blocks regular users from binding host paths into containers they create through the Portainer-mediated Docker API.
Leer descripción completaMostrar menos
The check that enforces this setting only inspected the legacy HostConfig.Binds array on the container-create proxy and never looked at the equivalent HostConfig.Mounts array. Any authenticated user with rights to create containers on a Docker environment where the restriction is enabled could submit a bind-typed entry under HostConfig.Mounts and mount any host path into their container. This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
- Puntuación base: 8.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.30%
- Percentil entre todas las CVEs puntuadas: 21
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access80 % - Impacto secundario
T1005Data from Local Systemcollection75 %
CVE-2026-44850: Vulnerabilidad de autorización en servicios remotos (Docker API proxied por Portainer) que requiere autenticación (PR:L) y permite a usuarios autenticados eludir restricciones de montaje para acceder a datos del host (C:H, CWE-863 Missing Authorization).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-44850",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-44850",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-29T19:08:08.089094Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.7,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "portainer",
"product": "portainer",
"versions": [
{
"status": "affected",
"version": ">= 2.33.0, < 2.33.8"
},
{
"status": "affected",
"version": ">= 2.39.0, < 2.39.2"
},
{
"status": "affected",
"version": ">= 2.40.0, < 2.41.0"
}
]
}
]
}
],
"published": "2026-05-28T22:16:59.107",
"references": [
{
"url": "https://github.com/portainer/portainer/security/advisories/GHSA-7fw3-x4r2-g7wc",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an environment-level Disable bind mounts for non-administrators security setting that blocks regular users from binding host paths into containers they create through the Portainer-mediated Docker API. The check that enforces this setting only inspected the legacy HostConfig.Binds array on the container-create proxy and never looked at the equivalent HostConfig.Mounts array. Any authenticated user with rights to create containers on a Docker environment where the restriction is enabled could submit a bind-typed entry under HostConfig.Mounts and mount any host path into their container. This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0."
},
{
"lang": "es",
"value": "Portainer Community Edition es una plataforma ligera de entrega de servicios para aplicaciones en contenedores que puede usarse para gestionar entornos Docker, Swarm, Kubernetes y ACI. Desde 2.33.0 hasta antes de 2.33.8, 2.39.2 y 2.41.0, Portainer ofrece una configuración de seguridad a nivel de entorno Deshabilitar montajes de enlace para no administradores que impide a los usuarios regulares enlazar rutas de host en los contenedores que crean a través de la API de Docker mediada por Portainer. La comprobación que aplica esta configuración solo inspeccionaba el array HostConfig.Binds heredado en el proxy de creación de contenedores y nunca examinó el array HostConfig.Mounts equivalente. Cualquier usuario autenticado con derechos para crear contenedores en un entorno Docker donde la restricción está habilitada podría enviar una entrada de tipo enlace bajo HostConfig.Mounts y montar cualquier ruta de host en su contenedor. Esta vulnerabilidad se corrige en 2.33.8, 2.39.2 y 2.41.0."
}
],
"lastModified": "2026-07-21T10:10:00.103",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:portainer:portainer:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E7FE81D-D489-4034-9DB4-D48E3B6C3CE4",
"versionEndExcluding": "2.33.8",
"versionStartIncluding": "2.33.0"
},
{
"criteria": "cpe:2.3:a:portainer:portainer:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3717D3CE-5226-41F7-A131-7CCAF164914D",
"versionEndExcluding": "2.39.1",
"versionStartIncluding": "2.34.0"
},
{
"criteria": "cpe:2.3:a:portainer:portainer:2.40.0:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "69F71AFC-F50D-4D10-9918-413D8E841CC2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}