CVE-2026-18255: Red Hat Quay 3.10

High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.

Affected products

  • Red Hat Red Hat Quay 3.10: before 1788561841 (fixed in 1788561841)
  • Red Hat Red Hat Quay 3.12: before 1788594376 (fixed in 1788594376)
  • Red Hat Red Hat Quay 3.14: before 1788593843 (fixed in 1788593843)
  • Red Hat Red Hat Quay 3.15: before 1788191755 (fixed in 1788191755)
  • Red Hat Red Hat Quay 3.16: before 1789563753 (fixed in 1789563753)
  • Red Hat Red Hat Quay 3.17: before 1790690298 (fixed in 1790690298)
  • Red Hat Red Hat Quay 3.9: before 1788595574 (fixed in 1788595574)

Published 2026-07-29. Last modified 2026-10-01.