THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x626-fcwx-f5pc (high) — Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

[GHSA] GHSA-x626-fcwx-f5pc (high) — Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

medgithub_advisoriesPublished 2026-08-28

GHSA-x626-fcwx-f5pc Severity: high CVE: CVE-2026-55761

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

## Summary Portainer supports restoring an instance from a backup archive via the /api/restore endpoint. This endpoint is intentionally unauthenticated to allow restoring before the first admin account is created, and remains accessible for t

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x626-fcwx-f5pc