Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

nvd логотип

CVE-2026-55761

2 месяца назад

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access. This issue is fixed in versions 2.39.4 and 2.43.0.

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20260813-80-0054

около 1 месяца назад

Уязвимость portainer-ce

CVSS3: 5.8
EPSS: Низкий
redos логотип

ROS-20260813-73-0054

около 1 месяца назад

Уязвимость portainer-ce

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-x626-fcwx-f5pc

18 дней назад

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-55761

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access. This issue is fixed in versions 2.39.4 and 2.43.0.

CVSS3: 5.9
0%
Низкий
2 месяца назад
redos логотип
ROS-20260813-80-0054

Уязвимость portainer-ce

CVSS3: 5.8
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260813-73-0054

Уязвимость portainer-ce

CVSS3: 5.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-x626-fcwx-f5pc

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

CVSS3: 5.9
0%
Низкий
18 дней назад

Уязвимостей на страницу