← All Advisories

CVE-2026-18255

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-18255

Key Details

CVECVE-2026-18255
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-863 (Incorrect Authorization)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Quay 3.10
Red HatRed Hat Quay 3.12
Red HatRed Hat Quay 3.14
Red HatRed Hat Quay 3.15
Red HatRed Hat Quay 3.16
Red HatRed Hat Quay 3.17
Red HatRed Hat Quay 3.9
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-18255
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-18255