Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Mon, 05 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to retrieve these delegate tokens. This issue allows a restricted user to bypass read-only limitations and push arbitrary container images to private repositories, leading to privilege escalation. | |
| Title | Quay: quay: global read-only superuser can access build trigger write credentials | |
| First Time appeared |
Redhat
Redhat quay |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:/a:redhat:quay:3 | |
| Vendors & Products |
Redhat
Redhat quay |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-05T20:29:45.881Z
Reserved: 2026-10-05T13:52:15.828Z
Link: CVE-2026-105447
No data.
Status : Received
Published: 2026-10-05T21:16:34.650
Modified: 2026-10-05T21:16:34.650
Link: CVE-2026-105447
No data.
OpenCVE Enrichment
No data.