Description
A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to retrieve these delegate tokens. This issue allows a restricted user to bypass read-only limitations and push arbitrary container images to private repositories, leading to privilege escalation.
Published: 2026-10-05
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Monitor
AI Analysis

Impact

A flaw in Quay allows an authenticated read‑only administrator to retrieve repository write tokens through the build trigger API. By exposing these delegate tokens, the attacker can bypass read‑only restrictions and push arbitrary container images to private repositories, effectively raising the attacker’s privilege level within the system.

Affected Systems

Red Hat Quay 3 (no specific version information is provided).

Risk and Exploitability

The vulnerability has a moderate CVSS score of 5.5 and is not currently listed in the CISA KEV catalog, with no EPSS score available. The exploit requires an authenticated read‑only superuser with access to the build trigger endpoint; an attacker can call this API, harvest the write tokens, and push images. The lack of proper authorization checks (CWE‑863) makes the attack straightforward once credentials are obtained.

Generated by OpenCVE AI on October 5, 2026 at 22:53 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Review build trigger configurations to eliminate exposed write tokens and enforce stricter access controls on the build trigger API.
  • Monitor vendor announcements for updates addressing this vulnerability and plan for future remediation.
  • If a fix becomes available, apply it and restart the Quay service to invalidate stale token data.

Generated by OpenCVE AI on October 5, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to retrieve these delegate tokens. This issue allows a restricted user to bypass read-only limitations and push arbitrary container images to private repositories, leading to privilege escalation.
Title Quay: quay: global read-only superuser can access build trigger write credentials
First Time appeared Redhat
Redhat quay
Weaknesses CWE-863
CPEs cpe:/a:redhat:quay:3
Vendors & Products Redhat
Redhat quay
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-05T20:29:45.881Z

Reserved: 2026-10-05T13:52:15.828Z

Link: CVE-2026-105447

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T21:16:34.650

Modified: 2026-10-05T21:16:34.650

Link: CVE-2026-105447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T23:00:19Z

Weaknesses