Impact
Unauthenticated access to the /api/restore endpoint and the /api/users/admin/init endpoint remains available during the five-minute setup window for uninitialized Portainer Community Edition instances. An attacker can craft and restore a malicious backup or create the first administrator account, thereby obtaining unrestricted administrative privileges. This represents an authentication bypass flaw (CWE-287).
Affected Systems
Portainer Community Edition releases 2.39.0 through 2.39.3 and 2.40.0 through 2.43.0 are affected; the flaw exists only while the instance is still uninitialized.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, and the EPSS score of less than 1% signals a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. A network attacker with visibility during the initial configuration window can exploit the unauthenticated endpoints to establish full administrative control over the uninitialized environment.
OpenCVE Enrichment