What is CVE-2026-18255?
A flaw in Quay allows users in the GLOBAL_READONLY_SUPER_USERS list to view robot account tokens for repositories they do not belong to. An attacker with read-only superuser privileges can impersonate any robot account. Quay administrators should review members of this group and apply the security update.
Azərbaycanca: Quay konteyner registrində aşkarlanan bu boşluq, GLOBAL_READONLY_SUPER_USERS siyahısındakı istifadəçilərə üzv olmadıqları repozitoriyaların robot hesab tokenlərini görməyə imkan verir. Təcavüzkar yalnız oxuma səlahiyyətinə malik superistifadəçi kimi istənilən robot hesabı təqlid edə bilər. Quay administratorları bu səlahiyyət qrupundakı istifadəçiləri nəzərdən keçirməli və təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which user group is affected by CVE-2026-18255?
Users in the GLOBAL_READONLY_SUPER_USERS list are affected by this flaw, as they can view and impersonate robot account tokens for repositories they do not belong to.
What can an attacker do by exploiting CVE-2026-18255?
An attacker with read-only superuser privileges can impersonate any robot account.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.