Missing Authorization Affecting github.com/portainer/portainer/api/http/proxy/factory/docker package, versions >=2.33.0 <2.33.8>=2.39.0 <2.39.2>=2.40.0 <2.41.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.33% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMPORTAINERPORTAINERAPIHTTPPROXYFACTORYDOCKER-17709252
  • published30 Jun 2026
  • disclosed14 May 2026
  • creditUnknown

Introduced: 14 May 2026

CVE-2026-44848  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade github.com/portainer/portainer/api/http/proxy/factory/docker to version 2.33.8, 2.39.2, 2.41.0 or higher.

Overview

github.com/portainer/portainer/api/http/proxy/factory/docker is a management UI which allows to manage different Docker environments.

Affected versions of this package are vulnerable to Missing Authorization in the executeDockerRequest process. An attacker can gain root-level access to the host system by installing and enabling malicious Docker plugins through unauthorized API calls. This is only exploitable if a non-admin authenticated user has been granted Docker endpoint access via RBAC.

Workaround

This vulnerability can be mitigated by temporarily revoking Docker endpoint access for non-admin users via Portainer RBAC until the patched release is deployed.

CVSS Base Scores

version 4.0
version 3.1