Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55761

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access. This issue is fixed in versions 2.39.4 and 2.43.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:portainer:portainer:*:*:*:*:community:*:*:*
Версия от 2.39.0 (включая) до 2.39.4 (исключая)
cpe:2.3:a:portainer:portainer:*:*:*:*:community:*:*:*
Версия от 2.40.0 (включая) до 2.43.0 (исключая)

EPSS

Процентиль: 41%
0.00493
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.8
redos
около 1 месяца назад

Уязвимость portainer-ce

CVSS3: 5.8
redos
около 1 месяца назад

Уязвимость portainer-ce

CVSS3: 5.9
github
18 дней назад

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

EPSS

Процентиль: 41%
0.00493
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287
NVD-CWE-noinfo