Missing Authorization Affecting github.com/portainer/portainer/api/http/proxy/factory/docker package, versions >=2.33.0 <2.33.8>=2.39.0 <2.39.2>=2.40.0 <2.41.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.35% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMPORTAINERPORTAINERAPIHTTPPROXYFACTORYDOCKER-16734125
  • published18 May 2026
  • disclosed14 May 2026
  • creditJohannesLks, route2shell

Introduced: 14 May 2026

CVE-2026-44849  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade github.com/portainer/portainer/api/http/proxy/factory/docker to version 2.33.8, 2.39.2, 2.41.0 or higher.

Overview

github.com/portainer/portainer/api/http/proxy/factory/docker is a management UI which allows to manage different Docker environments.

Affected versions of this package are vulnerable to Missing Authorization in the enforcement of endpoint security restrictions for non-admin users on Docker Swarm endpoints. An attacker can gain elevated privileges and access to the host filesystem by creating or updating Swarm services with unrestricted Linux capabilities, sysctls, security options, or bind mounts, bypassing administrator-imposed security policies. This is only exploitable if a non-admin user has been granted access to a Docker Swarm endpoint via RBAC and the administrator has configured restrictions such as AllowContainerCapabilitiesForRegularUsers, AllowSysctlSettingForRegularUsers, AllowSecurityOptForRegularUsers, or AllowBindMountsForRegularUsers.

Workaround

This vulnerability can be mitigated by temporarily revoking Swarm endpoint access for non-admin users via RBAC, segregating manager and worker nodes to limit exposure, or blocking creation of local-driver volumes that use 'type: none' / 'o: bind' on untrusted endpoints via a daemon-side allowlist.

CVSS Base Scores

version 4.0
version 3.1