{"id":"GHSA-rrmm-9v76-h3p4","summary":"Portainer missing authorization on Docker plugin endpoints, which allows host RCE","details":"## Summary\n\nPortainer enforces Role-Based Access Control (RBAC) on top of the Docker API. The proxy layer routes incoming Docker API requests to per-resource handlers (containers, images, services, volumes, etc.) that apply authorization checks.\n\nThe Docker plugin management endpoints (`/plugins/*`) were not registered with a handler, so standard users with endpoint access could call privileged plugin operations — including installing and enabling plugins — directly against the underlying Docker daemon.\n\nThe vulnerability is exposed when a non-admin Portainer user (Standard User role, or any role granted endpoint-level access) has been given access to a Docker endpoint via Portainer RBAC. Administrators and users without Docker endpoint access are not affected.\n\nA regular user with access to a Docker endpoint can:\n\n- Pull an arbitrary plugin from any registry via `POST /plugins/pull`.\n- Grant it the privileges it requests, including `CAP_SYS_ADMIN` and host-path mounts.\n- Enable the plugin via `POST /plugins/{name}/enable`, at which point Docker runs the plugin with root privileges on the host.\n\nDocker plugins execute as root on the host and can request arbitrary host capabilities and mounts. Enabling a crafted plugin gives the user access to the host filesystem and equivalent to root on the Docker host.\n\n## Severity\n\n**Critical** — CVSS 9.4\n`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H`\n\n**CWE-862** — Missing Authorization\n\n## Affected Versions\n\nThe vulnerability exists in every Portainer release where the Docker API proxy uses the prefix-allowlist routing model — `/plugins` has never been in the allowlist, and the fall-through path has never applied authorization.\n\nFixes are included in the next release of each supported branch:\n\n| Branch              | First vulnerable | Fixed in   |\n|---------------------|------------------|------------|\n| 2.33.x (LTS)        | 2.33.0           | **2.33.8** |\n| 2.39.x (LTS)        | 2.39.0           | **2.39.2** |\n| 2.40.x (STS)        | 2.40.0           | **2.41.0** |\n\nPortainer LTS branches receive fixes for 6 months plus a 3-month overlap after the next LTS ships. STS releases are supported only until the next STS ships — the 2.40.x STS line ends with the 2.41.0 release. All releases **prior to 2.33.0 are end-of-life** and will not receive a fix; users on EOL versions should upgrade to a supported LTS branch.\n\n## Workarounds\n\nAdministrators who cannot immediately upgrade can reduce exposure by temporarily **revoking Docker endpoint access for non-admin users** via Portainer RBAC until the patched release is deployed. This eliminates the attack surface without disruption for administrators. This does not replace the fix.\n\n## Affected Code\n\n```go\n// api/http/proxy/factory/docker/transport.go (pre-fix)\n\nvar prefixProxyFuncMap = map[string]func(...){\n    \"build\":      ...,\n    \"configs\":    ...,\n    \"containers\": ...,\n    \"images\":     ...,\n    \"networks\":   ...,\n    \"nodes\":      ...,\n    \"secrets\":    ...,\n    \"services\":   ...,\n    \"swarm\":      ...,\n    \"tasks\":      ...,\n    \"v2\":         ...,\n    \"volumes\":    ...,\n}\n\nfunc (transport *Transport) ProxyDockerRequest(request *http.Request) (*http.Response, error) {\n    // ...\n    prefix := strings.Split(strings.TrimPrefix(unversionedPath, \"/\"), \"/\")[0]\n\n    if proxyFunc := prefixProxyFuncMap[prefix]; proxyFunc != nil {\n        return proxyFunc(transport, request, unversionedPath)  // authorized\n    }\n\n    return transport.executeDockerRequest(request)  // forwarded without authorization\n}\n```\n\n`/plugins` is not in `prefixProxyFuncMap`, so requests to plugin endpoints fall through to `executeDockerRequest` and are forwarded to the Docker daemon without any Portainer-side authorization check.\n\n\n## Impact\n\nAn authenticated, non-admin Portainer user with access to any Docker-enabled endpoint can:\n\n- Install and enable arbitrary Docker plugins from any registry.\n- Execute plugin code with root privileges on the Docker host (including declaring `CAP_SYS_ADMIN` and host-path mounts).\n- Read and modify files on the host filesystem from a restricted account, overriding the administrator's security policy.\n\n## Timeline\n\n- 2026-03-16: Reported via GitHub Security Advisory by **ikkebr**.\n- 2026-04-20: Fix merged to `develop`, `release/2.39`, and `release/2.33`.\n- 2026-04-29: 2.41.0 released.\n- 2026-05-07: 2.39.2-LTS and 2.33.8-LTS released.\n\n## Credit\n\n- **ikkebr** — identified and reported the proxy allowlist bypass affecting the Docker plugin management endpoints.","aliases":["CVE-2026-44848","GO-2026-5639"],"modified":"2026-06-25T23:11:35.178741795Z","published":"2026-05-14T16:22:50Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-14T16:22:50Z","nvd_published_at":"2026-05-28T22:16:58Z","cwe_ids":["CWE-862"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/portainer/portainer/security/advisories/GHSA-rrmm-9v76-h3p4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44848"},{"type":"PACKAGE","url":"https://github.com/portainer/portainer"},{"type":"WEB","url":"https://github.com/portainer/portainer/releases/tag/2.33.8"},{"type":"WEB","url":"https://github.com/portainer/portainer/releases/tag/2.39.2"},{"type":"WEB","url":"https://github.com/portainer/portainer/releases/tag/2.41.0"}],"affected":[{"package":{"name":"github.com/portainer/portainer","ecosystem":"Go","purl":"pkg:golang/github.com/portainer/portainer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.33.0"},{"fixed":"2.33.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-rrmm-9v76-h3p4/GHSA-rrmm-9v76-h3p4.json"}},{"package":{"name":"github.com/portainer/portainer","ecosystem":"Go","purl":"pkg:golang/github.com/portainer/portainer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.39.0"},{"fixed":"2.39.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-rrmm-9v76-h3p4/GHSA-rrmm-9v76-h3p4.json"}},{"package":{"name":"github.com/portainer/portainer","ecosystem":"Go","purl":"pkg:golang/github.com/portainer/portainer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.40.0"},{"fixed":"2.41.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-rrmm-9v76-h3p4/GHSA-rrmm-9v76-h3p4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}