{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/red-hat-quay-3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-18255"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Red Hat Quay 3"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","container-security","auth-bypass"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-18255 affects Red Hat Quay 3. The issue stems from an incorrect authorization flaw (CWE-863) where users assigned to the GLOBAL_READONLY_SUPER_USERS role can improperly access and view robot account tokens associated with repositories they do not own or possess membership in. By successfully retrieving these tokens, an attacker with read-only superuser privileges can impersonate any robot account within the environment, effectively bypassing intended access restrictions. This vulnerability poses a significant risk to the integrity and confidentiality of container image registries managed by Red Hat Quay. Administrators should prioritize identifying users with excessive read-only privileges and applying relevant security patches provided by Red Hat to mitigate this privilege escalation vector.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized impersonation of robot accounts, which may be used for automated image pulls, pushes, or other CI/CD pipeline activities. Depending on the privileges granted to the targeted robot accounts, this could lead to the unauthorized exfiltration of container images or the injection of malicious images into repositories, impacting the software supply chain of affected organizations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Red Hat Quay 3 instances to the latest security version provided by Red Hat to remediate CVE-2026-18255.\u003c/li\u003e\n\u003cli\u003eReview the list of users configured within the GLOBAL_READONLY_SUPER_USERS role and apply the principle of least privilege.\u003c/li\u003e\n\u003cli\u003eAudit access logs for unusual patterns of repository access or API token retrieval by administrative accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T17:17:44Z","date_published":"2026-07-29T17:17:44Z","id":"https://feed.craftedsignal.io/briefs/2026-07-quay-auth-bypass/","summary":"An incorrect authorization vulnerability in Red Hat Quay allows read-only superusers to view and impersonate robot account tokens, potentially leading to unauthorized repository access.","title":"Authorization Bypass in Red Hat Quay","url":"https://feed.craftedsignal.io/briefs/2026-07-quay-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Red Hat Quay 3","version":"https://jsonfeed.org/version/1.1"}