2.39.7
Release 2.39.7 LTS
Security 2
- Fixed a critical Docker proxy authorization bypass where unrecognised API version prefixes like /v1.47.0/ or /v01.47/ skipped access control entirely, letting non-admin users reach the Docker API directly
- Closed a remaining gap in the CVE-2026-44849 (GHSA-5fxq-qcf3-244w) fix and broadened bind-mount restrictions for non-admin users, now including Compose and Swarm stack deployments
From Portainer
Known issues
- On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
Known issues with Podman support
- Podman environments aren't supported by auto-onboarding script
- It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
- Support for only CentOS 9, Podman 5 rootful
Changes
- Fixed a critical Docker proxy authorization bypass. Unrecognised API version prefixes like
/v1.47.0/or/v01.47/skipped access control entirely, letting non-admin users reach the Docker API directly - Closed a remaining gap in the CVE-2026-44849 (GHSA-5fxq-qcf3-244w) fix and broadened bind-mount restrictions for non-admin users, now including Compose and Swarm stack deployments
Deprecated and removed features
Deprecated features
- None
Removed features
- None