THREAT OPS › Threat News › [GHSA] GHSA-x626-fcwx-f5pc (high) — Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
[GHSA] GHSA-x626-fcwx-f5pc (high) — Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
GHSA-x626-fcwx-f5pc Severity: high CVE: CVE-2026-55761
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
## Summary Portainer supports restoring an instance from a backup archive via the /api/restore endpoint. This endpoint is intentionally unauthenticated to allow restoring before the first admin account is created, and remains accessible for t
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55761cve
Original source: https://github.com/advisories/GHSA-x626-fcwx-f5pc