Junglewise Threat Intelligence

CVE-2026-6848: Red Hat Quay authentication bypass in sensitive operations re-verification

CVE-2026-6848 · Severity: medium · CVSS 5.4 · Published 2026-04-22

Technologies: Redhat Quay, Red Hat Quay config-tool. Vendors: Redhat, Red Hat.

Executive brief

Red Hat Quay, a container image registry, contains a flaw where sensitive security prompts can be bypassed. When the system asks a user to re-enter their password for high-risk actions like creating robot accounts or generating access tokens, the action may succeed even if the password is wrong or missing. This could allow an unauthorized person with access to an unattended browser session to perform administrative tasks and gain persistent access to the registry.

Technical details

An authentication bypass vulnerability exists in Red Hat Quay's re-verification mechanism (CWE-613). When the application triggers a password prompt for sensitive operations—such as robot account creation or token generation—the backend fails to properly validate the success of this re-authentication before executing the requested action. While the UI may display an error message for invalid credentials, the underlying API request is processed successfully. This allows an attacker with access to an existing (but timed-out or idle) authenticated session to bypass 'sudo-mode' style protections. The flaw affects both the legacy and new Quay user interfaces.

Affected products

  • Red Hat Quay 3.0.0

Timeline

  • 2026-04-21: other: Reported to Red Hat Bugzilla
  • 2026-04-22: disclosed: Initial vulnerability disclosure
  • 2026-05-20: advisory: NVD analysis and enrichment

References

Related threats