Authentication Bypass Vulnerability in Portainer CE by Portainer
CVE-2026-72533
8.8HIGH
What is CVE-2026-72533?
An authentication bypass vulnerability present in Portainer CE version 2.44.0 enables low-privileged users to circumvent Docker proxy authorization checks. This is made possible through non-canonical URL normalization, leading to inconsistent request handling by the proxy and the authorization layer. As a result, attackers can exploit this flaw to gain root-level access to the Docker host, posing significant security threats to affected systems.
Affected Version(s)
Portainer CE 0 <= 2.44.0
