What is CVE-2026-74243?
Found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint, allowing them to flood the notification queue and inject path traversal characters.
Azərbaycanca: Red Hat Quay-da aşkar edilmişdir. Əgər SECURITY_SCANNER_V4_PSK təyin edilməyibsə, uzaqdan autentifikasiya olunmamış hücumçu təhlükəsizlik skanerinin bildiriş endpoint-nə POST sorğuları göndərərək bildiriş növbəsini doldurub path traversal simvolları yeridə bilər.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
Does exploiting CVE-2026-74243 require authentication?
No, this vulnerability allows a remote unauthenticated attacker to exploit it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.