GPU VulnDB

Database/Container, Kubernetes & orchestration

Portainer CE: non-canonical URL path defeats Docker proxy authorization, granting root on the Docker host

CVE-2026-72533Container, Kubernetes & orchestrationcurated

Impact

The Docker proxy endpoint applies access control before normalizing the request path, so the proxy and the authorization layer disagree about what is being called and crafted paths slip past every authorization middleware. A low-privileged Portainer user - a tenant given a scoped environment or a single stack - reaches the raw Docker API and can create a privileged container, which is root on the underlying host. On a GPU node that means the attacker owns the device nodes, the driver interfaces and any other tenant's containers scheduled there, and the host must be treated as compromised rather than merely restarted. Affects Portainer CE through 2.44.0.

Who can reach it

Any authenticated Portainer user, including the lowest privilege level, who can reach the Portainer web interface over the network. No administrator role and no local access needed.

What to do

The record cites only the project repository and names no fixed release beyond 2.44.0 - check the Portainer release notes for a version after 2.44.0 and upgrade, which is a container image replacement and Portainer restart. Until a fixed build is confirmed, remove non-admin Portainer accounts, restrict who can reach the interface, and treat any host managed by an exposed Portainer as potentially compromised.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.