Quay Read-Only Superuser Token Disclosure via GLOBAL_READONLY_SUPER_USERS
CVE-2026-18255 Published on July 29, 2026
Quay: quay: global read-only superuser can view robot account tokens
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.
Vulnerability Analysis
CVE-2026-18255 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-18255 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-18255
Want to know whenever a new CVE is published for Red Hat Quay? stack.watch will email you.