Security Advisory

CVE-2026-33590

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-28 19:30:06
Last updated 2026-06-12 15:02:52
Assigner ENISA
CVSS score 8.5
State PUBLISHED

Description

Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with endpoint access can exploit these settings to read host files or obtain root equivalent access on the host.