Impact
Tugtainer, a self‑hosted tool for automatic Docker container updates, has a flaw that allows anyone to reach its Agent Docker management APIs without authentication when no AGENT_SECRET is provided. The agent’s signature verification returns success if the secret is empty, effectively bypassing all protected routes. An attacker who can reach the Agent endpoint can issue Docker commands—create, stop, remove containers, execute arbitrary commands, or pull malicious images—resulting in complete compromise of the host system.
Affected Systems
The issue affects all installations of Quenary’s Tugtainer software running a version older than 1.30.4, regardless of other configuration, when the AGENT_SECRET setting is missing or empty. This includes deployments where the agent is exposed to a network and the secret is not explicitly set.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, reflecting a critical level of risk, and currently has no EPSS score available; it is not listed in CISA’s KEV catalog. Exploitation requires only network access to the Agent API and the condition that AGENT_SECRET is unset, making the attack straightforward for anyone who can reach the service. The lack of authentication allows full Docker control, providing a direct path to remote code execution on the host system.
OpenCVE Enrichment