Description
A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations.
Published: 2026-08-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the JWT validation logic in Red Hat Quay enables an attacker with a validly signed token from an identity provider to bypass security checks applied to federated robot accounts and single‑sign‑on authentication. The problem stems from incomplete audience verification and a failure to enforce the azp and sub claims, which normally restrict access to a specific client or subject. A successful bypass would allow the attacker to access resources that normally require the correct token claims, effectively compromising authentication controls.

Affected Systems

Products affected are Red Hat Quay 3 running on the Red Hat OpenShift Update Service. All current releases of Quay 3 could be impacted, as no version ranges were specified. Any deployment of Quay 3 with federated robot or SSO authentication enabled should verify whether the configuration includes proper audience, azp, and sub claim enforcement.

Risk and Exploitability

The CVSS score of 5.4 categorizes the vulnerability as moderate. EPSS is not available, so the likelihood of exploitation remains uncertain; no known exploits have been reported and the issue is not listed in CISA KEV. The primary attack vector is inferred to be possession of a validly signed token issued by the same identity provider; once such a token is obtained, the bypass can be performed with no additional privileges, granting unauthorized access.

Generated by OpenCVE AI on August 15, 2026 at 00:52 UTC.

Remediation

Vendor Workaround

To mitigate this issue, Red Hat Quay administrators should ensure that federated robot authentication is configured with specific audiences to enable 'verify_aud' enforcement. Additionally, review and update existing federation configurations to explicitly include and enforce 'azp' and 'sub' claims, preventing bypasses when these claims are absent. Refer to Red Hat Quay documentation for detailed configuration steps. A restart of affected Quay services may be required after configuration changes.


OpenCVE Recommended Actions

  • Configure federated robot authentication to use specific audiences so that verify_aud enforcement is enabled.
  • Update federation configurations to explicitly include and enforce the azp and sub claims.
  • Restart affected Quay services after making configuration changes.
  • Apply any vendor updates or patches that address the JWT validation flaw once they become available.

Generated by OpenCVE AI on August 15, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:redhat:openshift_update_service:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*

Mon, 17 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat quay 3
Vendors & Products Redhat quay 3

Sat, 15 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 14 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations.
Title Quay: jwt claim validation bypasses in quay federated robot and sso authentication
First Time appeared Redhat
Redhat openshift Update Service
Redhat quay
Weaknesses CWE-287
CPEs cpe:/a:redhat:openshift_update_service:5
cpe:/a:redhat:quay:3
Vendors & Products Redhat
Redhat openshift Update Service
Redhat quay
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Redhat Openshift Update Service Quay Quay 3
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-20T14:12:03.863Z

Reserved: 2026-08-14T19:46:37.190Z

Link: CVE-2026-74240

cve-icon Vulnrichment

Updated: 2026-08-20T14:11:59.199Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-14T23:16:33.960

Modified: 2026-08-20T19:45:42.220

Link: CVE-2026-74240

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-14T00:00:00Z

Links: CVE-2026-74240 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T10:30:08Z

Weaknesses