<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Red Hat Quay 3 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/red-hat-quay-3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 29 Jul 2026 17:17:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/red-hat-quay-3/feed.xml" rel="self" type="application/rss+xml"/><item><title>Authorization Bypass in Red Hat Quay</title><link>https://feed.craftedsignal.io/briefs/2026-07-quay-auth-bypass/</link><pubDate>Wed, 29 Jul 2026 17:17:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-quay-auth-bypass/</guid><description>An incorrect authorization vulnerability in Red Hat Quay allows read-only superusers to view and impersonate robot account tokens, potentially leading to unauthorized repository access.</description><content:encoded><![CDATA[<p>A security vulnerability identified as CVE-2026-18255 affects Red Hat Quay 3. The issue stems from an incorrect authorization flaw (CWE-863) where users assigned to the GLOBAL_READONLY_SUPER_USERS role can improperly access and view robot account tokens associated with repositories they do not own or possess membership in. By successfully retrieving these tokens, an attacker with read-only superuser privileges can impersonate any robot account within the environment, effectively bypassing intended access restrictions. This vulnerability poses a significant risk to the integrity and confidentiality of container image registries managed by Red Hat Quay. Administrators should prioritize identifying users with excessive read-only privileges and applying relevant security patches provided by Red Hat to mitigate this privilege escalation vector.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the unauthorized impersonation of robot accounts, which may be used for automated image pulls, pushes, or other CI/CD pipeline activities. Depending on the privileges granted to the targeted robot accounts, this could lead to the unauthorized exfiltration of container images or the injection of malicious images into repositories, impacting the software supply chain of affected organizations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update Red Hat Quay 3 instances to the latest security version provided by Red Hat to remediate CVE-2026-18255.</li>
<li>Review the list of users configured within the GLOBAL_READONLY_SUPER_USERS role and apply the principle of least privilege.</li>
<li>Audit access logs for unusual patterns of repository access or API token retrieval by administrative accounts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>container-security</category><category>auth-bypass</category></item></channel></rss>