Exposure of Sensitive Passwords in Tugtainer by Quenary
CVE-2026-23846
8.1HIGH
What is CVE-2026-23846?
Tugtainer, an application designed for automating Docker container updates, has a flaw present in versions before 1.16.1. This vulnerability arises from the incorrect handling of password authentication. Specifically, passwords are transmitted via URL query parameters rather than secured in the HTTP request body. As a result, sensitive information may be captured in server access logs and could potentially be exposed through browser histories, Referer headers, and proxy logs. Upgrading to version 1.16.1 mitigates this issue by ensuring safer password handling.
Affected Version(s)
tugtainer < 1.16.1
