What is CVE-2026-74242?
A flaw in Red Hat Quay allows an administrator of any repository to read notification configurations, including sensitive details such as webhook URLs, Slack tokens, and email addresses, by knowing or guessing the target notification's UUID. This vulnerability may lead to unauthorized access to sensitive configuration data. Applying the security update provided by Red Hat is recommended to mitigate this issue.
Azərbaycanca: Red Hat Quay-da aşkar edilmiş bu boşluq imkan verir ki, hər hansı bir repozitoriyanın administratoru, hədəf bildirişin UUID-sini bilib və ya təxmin edərək, webhook URL-ləri, Slack token-ləri və e-poçt ünvanları kimi həssas detalları özündə saxlayan bildiriş konfiqurasiyasını oxuya bilsin. Zəiflik həmçinin bildiriş konfiqurasiyasına icazəsiz girişlə nəticələnə bilər. Bu problemi aradan qaldırmaq üçün Red Hat tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Red Hat
FAQ2
What sensitive data can an attacker access by exploiting CVE-2026-74242?
An attacker can read notification configurations containing sensitive details such as webhook URLs, Slack tokens, and email addresses.
What measure should be taken to protect against CVE-2026-74242?
Applying the security update provided by Red Hat is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.