CVE-2026-33590

Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-05-28 20:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33590

Mitre link : CVE-2026-33590

CVE.ORG link : CVE-2026-33590


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions