Sceawere

Vulnerability Detail

CVE-2026-74242UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Red Hat Quay Notification Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
5h ago
Vendor
Red Hat
Product
Red Hat OpenShift Update Service
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to trigger test notifications for another repository. This could lead to unauthorized information disclosure and potential misuse of notification services.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-14T23:16:34.227Z",
  "pubdate": "2026-08-14T23:16:34.227Z",
  "executiveSummary": "A broken object level authorization (BOLA) vulnerability exists within Red Hat Quay related to its repository notification management system. The flaw enables an authenticated adversary with administrative privileges over a single arbitrary repository to access and retrieve notification configurations belonging to other foreign repositories. Exploitation of this security deficit relies upon the adversary knowing or successfully guessing the target notification's Universally Unique Identifier (UUID). Upon successful retrieval, the impacted system discloses sensitive administrative configuration details, including internal webhook URLs, authentication tokens destined for services like Slack, and external email addresses. Furthermore, the vulnerability grants unauthorized actors the capability to programmatically trigger test notifications destined for other repositories, potentially resulting in unauthorized resource consumption, external service misuse, or sensitive data leakage via outbound webhooks. The overall risk implication encompasses unauthorized information disclosure and service manipulation within multi-tenant or multi-repository environments. Mitigation requires implementing strict authorization checks that validate whether the requesting administrative user possesses direct ownership or explicit access rights to the targeted notification UUID before fulfilling configuration read requests or executing test notification routines.",
  "technicalDetails": "The vulnerability stems from inadequate access control enforcement within the notification management endpoints of Red Hat Quay. Specifically, the application fails to adequately validate the association between the requesting administrator and the requested notification resource when referenced via its Universally Unique Identifier (UUID). The vulnerable component resides within the repository notification handling logic, which processes administrative requests directed at specific notification identifiers. Privilege requirements for exploitation mandate that the attacker holds administrator privileges on at least one repository within the Quay instance, granting baseline access to the application interface. However, the lack of proper object-level authorization checks allows this low-privilege administrator to bypass security boundaries. The attack flow proceeds as follows: First, the malicious actor obtains or systematically guesses the UUID of a notification configuration associated with a target repository they do not control. UUID guessing is facilitated if the generation mechanism utilizes weak entropy or predictable sequences, though brute-forcing or information leakage from secondary channels may also apply. Second, the attacker issues an unauthorized HTTP request to the notification retrieval endpoint, supplying the targeted notification UUID. Third, the Quay backend processes the request without validating authorization against the repository boundary, subsequently returning the full notification configuration payload in the response body. This payload contains highly sensitive metadata, including plaintext or reversibly encoded webhook URLs, Slack integration tokens, and notification recipient email addresses. Finally, leveraging the same unauthorized access context, the attacker can invoke functionality designed to trigger test notifications for the targeted foreign repository, causing the application to dispatch outbound requests containing configured payloads to external endpoints. The network exposure includes any interface exposing the Quay API endpoints used for repository notification administration. Post-exploitation impact encompasses unauthorized exposure of internal infrastructure details via webhook URLs, compromise of third-party integration accounts through leaked Slack tokens, and the potential weaponization of outbound test notification dispatch mechanisms to perform denial-of-service or SSRF-adjacent behaviors against external endpoints."
}
CVE-2026-74242: Red Hat Quay Notification Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere