What is CVE-2026-74240?
A vulnerability was found in Red Hat Quay's JWT validation for federated robot accounts and SSO authentication, involving improper verification of `aud`, `azp`, and `sub` claims. This flaw could allow an attacker with a valid token to bypass security mechanisms. Users are advised to apply security patches.
Azərbaycanca: Red Hat Quay platformasında federasiya edilmiş robot hesablar və SSO autentifikasiyası üçün JWT doğrulamasında `aud`, `azp` və `sub` iddialarının yoxlanılması ilə bağlı boşluq aşkarlanıb. Bu zəiflik, etibarlı tokenə sahib olan təcavüzkarın təsdiqləmə mexanizmlərindən yan keçməsinə şərait yarada bilər. İstifadəçilərə təhlükəsizlik yamalarını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Red Hat
FAQ2
Which platform does CVE-2026-74240 affect?
CVE-2026-74240 affects the Red Hat Quay platform.
Which JWT claims are improperly verified in CVE-2026-74240?
The vulnerability involves improper verification of the `aud`, `azp`, and `sub` claims.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.