Bug 2508454 (CVE-2026-18255) - CVE-2026-18255 quay: quay: Global read-only superuser can view robot account tokens
Summary: CVE-2026-18255 quay: quay: Global read-only superuser can view robot account ...
Keywords:
Status: NEW
Alias: CVE-2026-18255
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-29 15:52 UTC by OSIDB Bzimport
Modified: 2026-07-29 16:25 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-29 15:52:35 UTC
Reproduction steps:

1. Configure a user in GLOBAL_READONLY_SUPER_USERS only.
2. Confirm the same user is not present in SUPER_USERS.
3. Apply config and allow Quay/operator reconciliation.
4. Log in as that user.
5. Navigate to robot account management and token views for a repo they are not a member of.
6. Observe that token visibility is allowed.

Impact:
Read-only administrative users can perform actions beyond intended scope. Robot account tokens are persistent by default (they do not expire), and depending on configuration can grant read (pull), write (push), or admin level access to container image repositories.


Note You need to log in before you can comment on or make changes to this bug.