What is CVE-2026-74245?
CVE-2026-74245 is a flaw in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID, which could be intercepted from plaintext emails or webhook callbacks, may download exported action logs without proper authorization. This could lead to sensitive information disclosure.
Azərbaycanca: CVE-2026-74245 Red Hat Quay platformasının ixrac edilən loglar funksiyasında aşkarlanıb. Autentifikasiya olmamış şəxs, email və ya webhook callback-lərdən ələ keçirilə bilən etibarlı bir file ID istifadə edərək, icazəsiz hərəkət loglarını yükləyə bilər. Bu, məxfi məlumatların sızmasına səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Is authentication required to exploit CVE-2026-74245?
No, an unauthenticated attacker can download exported action logs using a valid file ID.
How can the file ID be intercepted?
The file ID can be intercepted from plaintext emails or webhook callbacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.