Junglewise Threat Intelligence

CVE-2026-74241: Red Hat Quay LDAP injection in external authentication

CVE-2026-74241 · Severity: medium · CVSS 4.8 · Published 2026-08-14

Technologies: Red Hat Quay config-tool, Redhat Quay. Vendors: Red Hat, Redhat.

Executive brief

Red Hat Quay is a container image registry platform that organizations use to store and manage container images. This vulnerability allows attackers to inject malicious commands into LDAP authentication queries when the system processes LDAP referrals, potentially enabling them to discover which user accounts exist and manipulate authentication binding in multi-domain environments. While direct account compromise is limited, this flaw could facilitate targeted attacks and reconnaissance against organizational authentication infrastructure.

Technical details

The vulnerability is an LDAP injection (CWE-90) in Red Hat Quay's external LDAP authentication handler. When processing LDAP referrals during authentication, the system fails to properly escape username input before incorporating it into LDAP filter queries. An unauthenticated network attacker can craft malicious usernames containing LDAP metacharacters to conduct user-existence oracle attacks against referral DNs and potentially influence password binding DN selection in multi-domain Active Directory setups. The attack requires high attack complexity but does not require authentication or user interaction. While Red Hat reports no direct mitigation is available, patches may be released for future versions; currently affected systems should restrict LDAP referral processing or disable external LDAP authentication where feasible.

Affected products

  • Red Hat Quay <UNKNOWN>

Timeline

  • 2026-08-14: disclosed
  • 2026-08-14: advisory

References

Related threats