Skip to content
Red HatCVE-2026-18255

Quay. A user configured: improper authorization

High7.2CVE-2026-18255 · Published Jul 29, 2026 · updated Sep 22, 2026

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat BFD: out-of-bounds write
High7.8Jul 29
Red Hat Data Grid 8: missing authorization
Medium5.5Jul 29
Red Hat client policy enforcement mechanism of Keycloak: improper authorization
Medium6.5Jul 29
Red Hat CRIU: code injection
High7.8Jul 28
Red Hat sg3_utils. The sg_inq command: code execution
High7.6Jul 28
A flaw was found in openshift/oauth-proxy
High8.5Jul 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.