<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:45:08 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15956</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15956</link>
      <description>bdu:2026-15956</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15956</guid>
    </item>
    <item>
      <title>EUVD-2026-334005</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-334005</link>
      <description>EUVD-2026-334005</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-334005</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55761</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55761</link>
      <description>&lt;p&gt;Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access. This issue is fixed in versions 2.39.4 and 2.43.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access. This issue is fixed in versions 2.39.4 and 2.43.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55761</guid>
    </item>
    <item>
      <title>GHSA-x626-fcwx-f5pc — Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x626-fcwx-f5pc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/portainer/portainer&lt;/p&gt;
&lt;p&gt;## Summary
Portainer supports restoring an instance from a backup archive via the /api/restore endpoint. This endpoint is intentionally unauthenticated to allow restoring before the first admin account is created, and remains accessible for the five-minute initialization window that opens each time Portainer starts. Any unauthenticated attacker with network access to a Portainer instance that has not yet been initialised can exploit this window to replace the Portainer database with a crafted archive containing attacker-controlled credentials and gain full administrative access. The same unauthenticated setup window also exposes the administrator-account-creation endpoint (`/api/users/admin/init`), which an attacker can call to create the first administrator directly; the fix gates both endpoints.&lt;/p&gt;
&lt;p&gt;The attack requires the instance to be uninitialized, reachable by the attacker, and within the five-minute window. Once that window expires without initialization, Portainer locks its API and requires a restart to re-enable setup — each restart opens a fresh window. No credentials, session tokens, or local access are required.&lt;/p&gt;
&lt;p&gt;## Severity
**High**&lt;/p&gt;
&lt;p&gt;The endpoint requires no authentication and no user interaction, but successful exploitation depends on three conditions holding simultaneously: the instance must be uninitialized, reachable from the attacker&amp;#39;s network, and within the five-minute setup window that Portainer enforces before locking the instance pending a restart. Once…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/portainer/portainer&lt;/p&gt;
&lt;p&gt;## Summary
Portainer supports restoring an instance from a backup archive via the /api/restore endpoint. This endpoint is intentionally unauthenticated to allow restoring before the first admin account is created, and remains accessible for the five-minute initialization window that opens each time Portainer starts. Any unauthenticated attacker with network access to a Portainer instance that has not yet been initialised can exploit this window to replace the Portainer database with a crafted archive containing attacker-controlled credentials and gain full administrative access. The same unauthenticated setup window also exposes the administrator-account-creation endpoint (`/api/users/admin/init`), which an attacker can call to create the first administrator directly; the fix gates both endpoints.&lt;/p&gt;
&lt;p&gt;The attack requires the instance to be uninitialized, reachable by the attacker, and within the five-minute window. Once that window expires without initialization, Portainer locks its API and requires a restart to re-enable setup — each restart opens a fresh window. No credentials, session tokens, or local access are required.&lt;/p&gt;
&lt;p&gt;## Severity
**High**&lt;/p&gt;
&lt;p&gt;The endpoint requires no authentication and no user interaction, but successful exploitation depends on three conditions holding simultaneously: the instance must be uninitialized, reachable from the attacker&amp;#39;s network, and within the five-minute setup window that Portainer enforces before locking the instance pending a restart. Once…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x626-fcwx-f5pc</guid>
    </item>
  </channel>
</rss>
