Description
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.
Published: 2026-07-29
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Red Hat Quay allows a user assigned to the GLOBAL_READONLY_SUPER_USERS group to retrieve robot account tokens for any repository, even if that user has no membership in the repository. This exposure enables an attacker with such read‑only superuser privileges to impersonate any robot account, potentially gaining unauthorized access to container images or performing privileged actions within the organization.

Affected Systems

This issue affects Red Hat Quay 3. No specific patch release version is listed, so users should check with Red Hat for the latest update that addresses the flaw. The vulnerability is limited to instances where the GLOBAL_READONLY_SUPER_USERS role is misconfigured to include users who should not have access to robot tokens.

Risk and Exploitability

The CVSS score of 7.2 indicates a moderate to high severity, but the EPSS score of less than 1 % shows a very low current exploitation probability. The flaw is not listed in CISA KEV. By virtue of being a privileged role within Quay, the attack path does not require external network access; an attacker who can add or maintain a GLOBAL_READONLY_SUPER_USER can immediately view all robot tokens. The likely attack path is inferred directly from the description, as the specific external attack vector is not explicitly detailed in the CVE data.

Generated by OpenCVE AI on August 2, 2026 at 07:47 UTC.

Remediation

Vendor Workaround

Remove users who can not be trusted with robot account credentials from GLOBAL_READONLY_SUPER_USERS.


OpenCVE Recommended Actions

  • Upgrade to the latest Red Hat Quay release that contains the fix for this vulnerability.
  • Remove any users who should not be trusted with robot account credentials from the GLOBAL_READONLY_SUPER_USERS list, following the provided workaround.
  • Regularly audit repository membership and the GLOBAL_READONLY_SUPER_USERS list to ensure only authorized personnel retain those privileges.

Generated by OpenCVE AI on August 2, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat quay 3
Vendors & Products Redhat quay 3

Thu, 30 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.
Title Quay: quay: global read-only superuser can view robot account tokens
First Time appeared Redhat
Redhat quay
Weaknesses CWE-863
CPEs cpe:/a:redhat:quay:3
Vendors & Products Redhat
Redhat quay
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-29T18:05:53.353Z

Reserved: 2026-07-29T16:19:25.998Z

Link: CVE-2026-18255

cve-icon Vulnrichment

Updated: 2026-07-29T18:05:50.359Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T17:16:51.393

Modified: 2026-07-30T14:15:31.167

Link: CVE-2026-18255

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T14:34:20Z

Links: CVE-2026-18255 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:00:04Z

Weaknesses