Description
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access. This issue is fixed in versions 2.39.4 and 2.43.0.
Published: 2026-07-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated access to the /api/restore endpoint and the /api/users/admin/init endpoint remains available during the five-minute setup window for uninitialized Portainer Community Edition instances. An attacker can craft and restore a malicious backup or create the first administrator account, thereby obtaining unrestricted administrative privileges. This represents an authentication bypass flaw (CWE-287).

Affected Systems

Portainer Community Edition releases 2.39.0 through 2.39.3 and 2.40.0 through 2.43.0 are affected; the flaw exists only while the instance is still uninitialized.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, and the EPSS score of less than 1% signals a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. A network attacker with visibility during the initial configuration window can exploit the unauthenticated endpoints to establish full administrative control over the uninitialized environment.

Generated by OpenCVE AI on July 29, 2026 at 14:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to release 2.39.4 or later, which removes the unauthenticated restore and admin initialization endpoints.
  • Enforce firewall rules or network policies that block external traffic to the Portainer deployment during the initial setup window.
  • Deploy a temporary reverse proxy rule that denies unauthenticated requests to the /api/restore and /api/users/admin/init endpoints during the initial setup period.

Generated by OpenCVE AI on July 29, 2026 at 14:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Portainer
Portainer portainer
Vendors & Products Portainer
Portainer portainer

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access. This issue is fixed in versions 2.39.4 and 2.43.0.
Title Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Portainer Portainer
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-08T15:52:30.257Z

Reserved: 2026-06-17T14:34:51.880Z

Link: CVE-2026-55761

cve-icon Vulnrichment

Updated: 2026-07-08T15:52:19.532Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:15:03Z

Weaknesses