Sceawere

Vulnerability Detail

CVE-2026-74245UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Red Hat Quay Exported Logs Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
5h ago
Vendor
Red Hat
Product
Red Hat OpenShift Update Service
Attack Type
Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure, potentially exposing sensitive data such as usernames, email addresses, IP addresses, and action-specific metadata.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-08-14T23:16:34.600Z",
  "pubdate": "2026-08-14T23:16:34.600Z",
  "executiveSummary": "An information disclosure vulnerability has been identified within Red Hat Quay's exported logs feature, specifically affecting the mechanism handling exported action logs.\nThe flaw allows unauthenticated remote attackers in possession of a valid file ID to bypass access controls and download sensitive log data without proper authorization.\nThe impacted system is Red Hat Quay.\nSuccessful exploitation exposes critical operational metadata, including user names, email addresses, IP addresses, and action-specific metadata.\nAlthough file IDs are complex cryptographic strings, they lack adequate authorization checks upon retrieval and can be intercepted via plaintext transmission channels such as email notifications or webhook callbacks.\nThe risk implications include unauthorized surveillance of system events, exposure of personally identifiable information (PII), and leakage of network topology data.\nExploitation requires an attacker to intercept a valid, active file ID through insecure communication channels like plaintext email or unencrypted webhook payloads, followed by direct HTTP requests to the export retrieval endpoint without requiring authentication credentials.",
  "technicalDetails": "The vulnerability stems from a broken access control flaw within the exported action logs component of Red Hat Quay.\nThe root cause is the failure of the application to enforce proper session validation or authorization checks when processing download requests for exported log file IDs.\nThe affected component is the exported logs retrieval module.\nNetwork exposure is present wherever Red Hat Quay exposes its web interface and webhook notification systems.\nAuthentication requirements are bypassed due to the absence of token verification or session validation on the targeted download endpoint; the system implicitly trusts the supplied file ID as a bearer of authorization.\nPrivilege requirements are nonexistent, as an unauthenticated attacker can execute the request.\nThe attack flow begins when Red Hat Quay generates an exported action log and initiates a notification containing the file ID via plaintext email or webhook callbacks.\nAn intermediary network adversary or a compromised downstream mail server/webhook listener intercepts the plaintext transmission, extracting the complex file ID string.\nThe attacker then crafts an arbitrary HTTP request targeting the log download endpoint, appending the intercepted file ID to the request URI.\nUpon receiving the request, the vulnerable endpoint fails to verify whether the requesting entity owns or has been granted permission to access the specified file ID.\nThe application processes the request and streams the exported action logs directly to the attacker.\nThe payload behavior involves the retrieval of structured log data containing sensitive operational metadata.\nThe post-exploitation impact includes unauthorized information disclosure of internal usernames, associated email addresses, client IP addresses, and granular action-specific metadata, which can facilitate subsequent targeted attacks against the infrastructure or its users."
}
CVE-2026-74245: Red Hat Quay Exported Logs Information Disclosure (MEDIUM Severity, CVSS: 5.9) - Sceawere