Junglewise Threat Intelligence

CVE-2026-74245: Red Hat Quay authentication bypass in exported logs

CVE-2026-74245 · Severity: medium · CVSS 5.9 · Published 2026-08-14

Technologies: Red Hat Quay config-tool, Redhat Quay. Vendors: Red Hat, Redhat.

Executive brief

Red Hat Quay is a container image registry used by enterprises to store and manage Docker container images. A flaw in its exported logs feature allows unauthenticated attackers to download sensitive action logs if they obtain a file ID, which can be intercepted from plaintext emails or webhook callbacks. This could expose operational data including usernames, email addresses, IP addresses, and system activity, potentially aiding further attacks or creating compliance violations.

Technical details

This vulnerability is an authentication bypass (CWE-306) in Red Hat Quay's exported logs download mechanism. An unauthenticated attacker with knowledge of a file ID can directly access and download exported action logs without authorization checks. While file IDs are cryptographically complex, they are transmitted in plaintext via email notifications and webhook callbacks, creating an interception vector. Deployments using LocalStorage backends face heightened risk due to indefinite file persistence. The attack requires network access to Quay's API but no authentication credentials or user interaction. Red Hat recommends using cloud storage backends with time-limited download URLs and securing communication channels for log delivery.

Affected products

  • Red Hat Quay

Timeline

  • 2026-08-14: disclosed

References

Related threats