redhat openshift-update-service CVE-2026-74240 vulnerability in Red Hat Products
Published on August 14, 2026

Quay: jwt claim validation bypasses in quay federated robot and sso authentication
A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations.

NVD

Vulnerability Analysis

CVE-2026-74240 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
NONE

Timeline

Reported to Red Hat.

Made public. 11 days later.

Weakness Type

What is an authentification Vulnerability?

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CVE-2026-74240 has been classified to as an authentification vulnerability or weakness.


Products Associated with CVE-2026-74240

stack.watch emails you whenever new vulnerabilities are published in Red Hat Openshift Update Service or Red Hat Quay. Just hit a watch button to start following.

 
 

Affected Versions

Red Hat OpenShift Update Service: Red Hat Quay 3: Red Hat Quay 3: