Description
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to trigger test notifications for another repository. This could lead to unauthorized information disclosure and potential misuse of notification services.
Published: 2026-08-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an IDOR that allows an administrator of any repository to discover and read the configuration of a notification belonging to another repository by guessing or knowing the notification’s UUID. The discovered data can include webhook URLs, Slack tokens, and email addresses, and the attacker can also trigger test notifications for that other repository. These capabilities expose sensitive information and could be abused to compromise downstream services if the credentials or callbacks are actionable.

Affected Systems

Red Hat Quay 3 and Red Hat OpenShift Update Service are affected. No specific version range is listed in the CNA data, so all installations of these products may be vulnerable until a vendor patch is applied.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate impact. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation at the time of analysis. The likely attack vector requires local administrative access to a repository; an attacker who can impersonate or guess a UUID can read or execute notification actions. The absence of an official workaround means the risk remains until a vendor fix is released.

Generated by OpenCVE AI on August 15, 2026 at 00:50 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply any Red Hat security update for Quay 3 as soon as it becomes available
  • Limit repository administrative rights to trusted users and enforce least‑privilege access controls
  • Disable or remove notification endpoints that expose sensitive tokens or rotate any exposed secrets
  • Configure logging and alerts to detect unauthorized notification configuration access or test notification attempts
  • No workaround meets Red Hat Product Security criteria; rely on official patch until a viable mitigation is released

Generated by OpenCVE AI on August 15, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:redhat:openshift_update_service:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Quay 3
Vendors & Products Red Hat
Red Hat red Hat Quay 3

Sat, 15 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 14 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to trigger test notifications for another repository. This could lead to unauthorized information disclosure and potential misuse of notification services.
Title Quay: repository notification uuid idor in quay api
First Time appeared Redhat
Redhat openshift Update Service
Redhat quay
Weaknesses CWE-639
CPEs cpe:/a:redhat:openshift_update_service:5
cpe:/a:redhat:quay:3
Vendors & Products Redhat
Redhat openshift Update Service
Redhat quay
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Red Hat Red Hat Quay 3
Redhat Openshift Update Service Quay
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-17T17:57:39.606Z

Reserved: 2026-08-14T19:46:37.191Z

Link: CVE-2026-74242

cve-icon Vulnrichment

Updated: 2026-08-17T17:47:32.947Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-14T23:16:34.227

Modified: 2026-08-20T19:00:11.597

Link: CVE-2026-74242

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-14T00:00:00Z

Links: CVE-2026-74242 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T10:59:57Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key