GO-2026-6324
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer
Details
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/portainer/portainer from v2.39.0 before v2.39.4, from v2.40.0 before v2.43.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for github.com/portainer/portainer (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/portainer/portainer/security/advisories/GHSA-x626-fcwx-f5pc[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-55761[ADVISORY]
- https://github.com/portainer/portainer/commit/49f19107cf9a3540cbe406c9eb7f24390e1af02b[FIX]
- https://github.com/portainer/portainer/commit/d2b56efcb4e43c4168bb6688eee9f6bf22867312[FIX]
- https://github.com/portainer/portainer/issues/2770[REPORT]
- https://github.com/portainer/portainer/releases/tag/2.39.4[WEB]
- https://github.com/portainer/portainer/releases/tag/2.43.0[WEB]