Junglewise Threat Intelligence

CVE-2026-18255: Red Hat Quay incorrect authorization in GLOBAL_READONLY_SUPER_USERS

CVE-2026-18255 · Severity: high · CVSS 7.2 · Published 2026-07-29

Vendors: Red Hat.

Executive brief

Red Hat Quay, a platform for managing and storing container images, contains a security flaw that allows certain administrative users to view sensitive credentials they should not have access to. Specifically, users assigned to a 'read-only superuser' role can view the authentication tokens for 'robot accounts' across the entire platform, even for projects they do not belong to. An attacker with these credentials could impersonate these automated accounts to download, upload, or modify container images, potentially leading to unauthorized data access or the injection of malicious code into the software supply chain.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Red Hat Quay's management interface. The flaw resides in the access control logic for the GLOBAL_READONLY_SUPER_USERS role, which fails to restrict access to robot account tokens for repositories where the user lacks explicit membership. An attacker with high-privileged, read-only administrative access can exploit this to retrieve persistent robot account tokens. These tokens can grant pull, push, or administrative permissions to container repositories, allowing the attacker to bypass intended role-based access controls and impersonate automated service accounts. The vulnerability is reachable over the network and requires the attacker to already possess read-only superuser credentials.

Affected products

  • Red Hat Quay 3 3

Timeline

  • 2026-07-29: disclosed: Vulnerability reported and published by Red Hat

References