---
schema: 1
kind: vulnerability
title: "CVE-2026-44848 & CVE-2026-44849 — Portainer CE: Docker plugin endpoints unguarded; Swarm-service security checks bypassed (CVSS 9.4)"
headline: "CVE-2026-44848 & CVE-2026-44849 — Portainer CE: Docker plugin endpoints unguarded; Swarm-service security checks bypassed (CVSS 9.4)"
summary: "Portainer shipped CE 2.33.8 / 2.39.2 / 2.41.0 on 2026-05-28 closing two CVSS 9.4 authorization bypasses; CCB Belgium issued a \"Patch Immediately\" advisory on the same day. CVE-2026-44848 (GHSA-rrmm-9v76-h3p4) — the Docker plugin-management endpoints (/plugins/*) are not registered in Portainer's …"
discovered_at: "2026-05-29T05:00:08Z"
event_date: null
run_id: 2026-05-29-c7f56b00
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - auth-bypass
  - priv-esc
  - rce
  - patch-available
regions:
  - europe
  - global
sectors:
  - public-sector
  - technology
  - healthcare
entities: []
cves:
  - id: CVE-2026-44848
    cvss: "9.4"
    epss: null
    type: auth-bypass
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-44849
    cvss: "9.4"
    epss: null
    type: auth-bypass
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://github.com/portainer/portainer/security/advisories/GHSA-rrmm-9v76-h3p4"
    publisher: Portainer GHSA-rrmm-9v76-h3p4
    role: primary
  - url: "https://ccb.belgium.be/advisories/warning-two-critical-vulnerabilities-portainer-allow-full-host-takeover-patch"
    publisher: CCB Belgium — Patch Immediately
    role: corroborating
closed_sources: []
evidence:
  - quote: "Docker plugin management endpoints (/plugins/*) were not registered with a handler, so standard users with endpoint access could call privileged plugin operations — including installing and enabling plugins — directly against the underlying Docker daemon"
    publisher: Portainer GHSA-rrmm-9v76-h3p4
  - quote: "Warning: Two Critical Vulnerabilities in Portainer Allow Full Host Takeover, Patch Immediately!"
    publisher: Centre for Cybersecurity Belgium
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-29.md
---

Portainer shipped CE 2.33.8 / 2.39.2 / 2.41.0 on 2026-05-28 closing two CVSS 9.4 authorization bypasses; [CCB Belgium issued a *"Patch Immediately"* advisory](https://ccb.belgium.be/advisories/warning-two-critical-vulnerabilities-portainer-allow-full-host-takeover-patch) on the same day. [`CVE-2026-44848` (GHSA-rrmm-9v76-h3p4)](https://github.com/portainer/portainer/security/advisories/GHSA-rrmm-9v76-h3p4) — the Docker plugin-management endpoints (`/plugins/*`) are not registered in Portainer's proxy-authorization handler map, so any authenticated non-admin user with endpoint access can `POST /plugins/pull` to install a plugin from any registry and `POST /plugins/{name}/enable` to activate it; Docker runs enabled plugins as root on the host with the plugin's declared capabilities and mounts, giving OS-level code execution. `CVE-2026-44849` (GHSA-5fxq-qcf3-244w) — Portainer's seven `EndpointSecuritySettings` restrictions (privileged mode, host PID, device mapping, capabilities, sysctls, security-opt, bind mounts) are enforced on the standard container-create path but **not** on the Docker Swarm service API; `POST /services/create` validates only `Mounts[]` (1 of 7 checks), and `POST /services/{id}/update` performs no checks at all. Non-admin users can submit arbitrary `CapabilityAdd`, `Sysctls` and `Privileges` values; a volume-driver bypass additionally allows bind-mount equivalents via `Type: volume` with `VolumeOptions.DriverConfig.Options{type: none, o: bind}`. Affected: CE 2.33.0–2.33.7, 2.39.0–2.39.1, 2.40.x. Temporary mitigation: revoke Swarm endpoint access for non-admin users via Portainer RBAC, disable plugin management for non-admin users.
