CVE-2026-18255: Red Hat Quay 3.10
High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.
Affected products
- Red Hat Red Hat Quay 3.10: before 1788561841 (fixed in 1788561841)
- Red Hat Red Hat Quay 3.12: before 1788594376 (fixed in 1788594376)
- Red Hat Red Hat Quay 3.14: before 1788593843 (fixed in 1788593843)
- Red Hat Red Hat Quay 3.15: before 1788191755 (fixed in 1788191755)
- Red Hat Red Hat Quay 3.16: before 1789563753 (fixed in 1789563753)
- Red Hat Red Hat Quay 3.17: before 1790690298 (fixed in 1790690298)
- Red Hat Red Hat Quay 3.9: before 1788595574 (fixed in 1788595574)
Published 2026-07-29. Last modified 2026-10-01.