CVE-2026-72533

Source
https://cve.org/CVERecord?id=CVE-2026-72533
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72533.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72533
Published
2026-08-11T11:06:33.537Z
Modified
2026-08-13T04:03:01.535605466Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Portainer Portainer CE - Authentication Bypass
Details

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls, allowing crafted requests to be interpreted differently by the proxy and the authorization layer. Successful exploitation grants the attacker root-level access to the underlying Docker host.

Database specific
{
    "cwe_ids": [
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72533.json",
    "cna_assigner": "TuranSec"
}
References

Affected packages

Git / github.com/portainer/portainer

Affected ranges

Type
GIT
Repo
https://github.com/portainer/portainer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.44.0"
        },
        {
            "fixed": "2.44.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

1.*
1.11.3
1.20.0
2.*
2.0.0
2.23.0
internal-1.*
internal-1.2.0
internal-1.3.0
internal-1.4.0
internal-1.5.0
internal-1.6.0
v0.*
v0.5
v0.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72533.json"