Portainer provides a widely adopted web-based management interface for Docker and Kubernetes container orchestration platforms, positioning itself as a control plane for containerized infrastructure. The vendor's vulnerability profile concentrates in its flagship Portainer product and skews strongly toward critical-severity outcomes, reflecting the sensitive nature of container management and the broad operational access that the interface grants. The recurring weakness classes—cross-site scripting, authorization and access-control flaws, and path-traversal conditions—are characteristic of web-based administrative tools that must manage authentication at scale and defend against both direct and browser-based attacks. Defenders should treat Portainer advisories as high-priority given its privileged position in container environments, where a compromise can propagate across workload clusters; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Portainer over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44881CRITICAL Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Fro | May 28, 2026 | 9.9 | 40 | NO | NO |
CVE-2026-44850HIGH Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Fro | May 28, 2026 | 8.5 | 35 | NO | NO |
CVE-2026-44848HIGH Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Fro | May 28, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-44882HIGH Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Fro | May 28, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-44849HIGH Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Fro | May 28, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-44883HIGH Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Fro | May 28, 2026 | 7.5 | 31 | NO | NO |
CVE-2022-24961CRITICAL In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days. | Feb 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-24264CRITICAL Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on th | Mar 16, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-19466CRITICAL A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls. | Mar 27, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-19367CRITICAL Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created. This API endpoint will return 404 if admin was not crea | Nov 20, 2018 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Portainer.
Media articles that mention a CVE ID that affects a product developed by Portainer — matched by CVE ID, not by vendor name.