{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aportainerportainercommunity/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:portainer:portainer:*:*:*:*:*:*:*:*","cpe:2.3:a:portainer:portainer:*:*:*:*:community:*:*:*"],"_cs_cves":[{"cvss":5.9,"id":"CVE-2026-55761"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Portainer CE (2.39.0 \u003c= v \u003c 2.39.4, \u003c 2.43.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve-2026-55761","portainer","container-security"],"_cs_type":"advisory","_cs_vendors":["Portainer"],"content_html":"\u003cp\u003ePortainer is vulnerable to an authentication bypass during the five-minute initialization window that occurs when a new instance starts without an administrator account. The endpoints \u003ccode\u003e/api/restore\u003c/code\u003e and \u003ccode\u003e/api/users/admin/init\u003c/code\u003e were designed to be public to facilitate initial setup; however, they lack proper authentication, allowing any network-reachable attacker to either restore a malicious database containing pre-configured attacker credentials or directly create a new administrative user. This vulnerability, tracked as CVE-2026-55761, affects Portainer CE versions in the 2.39.x branch prior to 2.39.4 and 2.43.x branch prior to 2.43.0. Versions prior to 2.39.0 are end-of-life and remain vulnerable. Successful exploitation results in full administrative control over the Portainer instance, which typically grants root-level access to the underlying Docker host or Kubernetes environment, along with access to all stored secrets and registered edge agents.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network scanning to identify uninitialized Portainer instances reachable over the network.\u003c/li\u003e\n\u003cli\u003eAttacker restarts the identified Portainer instance or waits for a restart to trigger the five-minute initialization window.\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to the \u003ccode\u003e/api/users/admin/init\u003c/code\u003e endpoint to create a new, attacker-controlled administrative account.\u003c/li\u003e\n\u003cli\u003eAlternatively, attacker sends a POST request to the \u003ccode\u003e/api/restore\u003c/code\u003e endpoint to overwrite the database with a crafted archive containing malicious administrative credentials.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the Portainer web interface using the newly created credentials.\u003c/li\u003e\n\u003cli\u003eAttacker leverages Portainer's administrative permissions to deploy a container with host filesystem mounting capabilities.\u003c/li\u003e\n\u003cli\u003eAttacker executes commands within the container to escape to the host OS with root privileges.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates stored registry credentials, API keys, and environment variables from the Portainer instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an attacker full administrative access to a Portainer instance, enabling them to compromise every registered Docker host, Kubernetes cluster, or edge agent. Because Portainer typically manages the Docker socket (\u003ccode\u003e/var/run/docker.sock\u003c/code\u003e), an attacker can easily execute arbitrary code on the underlying host, leading to full system compromise. Furthermore, the attacker gains access to all managed credentials, environment variables, and stored secrets within the environment, providing significant opportunities for lateral movement and long-term persistence.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Portainer instances to the fixed versions (2.39.4 for the 2.39.x branch or 2.43.0 for the 2.43.x branch) to implement the required X-Setup-Token header authentication for initialization endpoints.\u003c/li\u003e\n\u003cli\u003eFor new deployments, use the \u003ccode\u003e--admin-password\u003c/code\u003e or \u003ccode\u003e--admin-password-file\u003c/code\u003e configuration flags to provision the administrator account during initial startup, which prevents the instance from entering the vulnerable uninitialized state.\u003c/li\u003e\n\u003cli\u003eImplement network-layer restrictions (e.g., firewall rules, VPC security groups) to isolate Portainer instances from untrusted networks until the initial setup process is complete and an admin account is established.\u003c/li\u003e\n\u003cli\u003eAudit existing Portainer deployments for the presence of unauthorized administrative accounts or anomalous activity originating from local account creation events.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:14:03Z","date_published":"2026-08-28T21:14:03Z","id":"https://feed.craftedsignal.io/briefs/2026-08-portainer-auth-bypass/","summary":"An authentication bypass vulnerability in Portainer allows unauthenticated attackers to hijack uninitialized instances via the /api/restore and /api/users/admin/init endpoints.","title":"Unauthenticated Admin Takeover in Portainer Initialization","url":"https://feed.craftedsignal.io/briefs/2026-08-portainer-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:portainer:portainer:*:*:*:*:community:*:*:*","version":"https://jsonfeed.org/version/1.1"}