Junglewise Threat Intelligence

CVE-2026-74242: Red Hat Quay notification UUID authorization bypass

CVE-2026-74242 · Severity: medium · CVSS 5.3 · Published 2026-08-14

Technologies: Red Hat Quay config-tool, Redhat Quay. Vendors: Red Hat, Redhat.

Executive brief

Red Hat Quay is a container image registry platform used by enterprises to store and manage containerized applications. A vulnerability allows authenticated repository administrators to access notification configurations of other repositories by guessing a notification's unique identifier, exposing sensitive data like webhook URLs and authentication tokens. This could enable attackers to discover credentials or interfere with notification systems across the platform.

Technical details

This is an insecure direct object reference (IDOR) vulnerability in Red Hat Quay's notification API. An authenticated repository administrator can read notification configurations of any repository by knowing or guessing a 128-bit notification UUID, bypassing authorization checks. The vulnerability also permits triggering test notifications for other repositories. The attack requires network access and valid repository admin credentials, but the 128-bit UUID space and lack of rate limiting make enumeration feasible. Red Hat rates this as Moderate impact due to the authentication requirement and UUID guessing complexity, though successful exploitation exposes sensitive webhook URLs, Slack tokens, and email addresses. No mitigation is currently available beyond upgrading to a patched version.

Affected products

  • Red Hat Quay

Timeline

  • 2026-08-14: disclosed

References

Related threats