HIGHGo →
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
Affected packages
- github.com/portainer/portainer
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/portainer/portainer/security/advisories/GHSA-x626-fcwx-f5pc
- https://nvd.nist.gov/vuln/detail/CVE-2026-55761
- https://github.com/portainer/portainer/issues/2770
- https://github.com/portainer/portainer/commit/49f19107cf9a3540cbe406c9eb7f24390e1af02b
- https://github.com/portainer/portainer/commit/d2b56efcb4e43c4168bb6688eee9f6bf22867312
- https://github.com/portainer/portainer
- https://github.com/portainer/portainer/releases/tag/2.39.4
- https://github.com/portainer/portainer/releases/tag/2.43.0
Structured record: https://osv.dev/vulnerability/GHSA-x626-fcwx-f5pc
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta