CVE-2026-18255 - Quay: quay: global read-only superuser can view robot account tokens
CVE ID :CVE-2026-18255
Published : July 29, 2026, 4:34 p.m. | 17 minutes ago
Description :A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 29, 2026, 4:34 p.m. | 17 minutes ago
Description :A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...