Exposure of Sensitive Passwords in Tugtainer by Quenary
CVE-2026-23846

8.1HIGH

Key Information:

Vendor

Quenary

Status
Vendor
CVE Published:
19 January 2026

What is CVE-2026-23846?

Tugtainer, an application designed for automating Docker container updates, has a flaw present in versions before 1.16.1. This vulnerability arises from the incorrect handling of password authentication. Specifically, passwords are transmitted via URL query parameters rather than secured in the HTTP request body. As a result, sensitive information may be captured in server access logs and could potentially be exposed through browser histories, Referer headers, and proxy logs. Upgrading to version 1.16.1 mitigates this issue by ensuring safer password handling.

Affected Version(s)

tugtainer < 1.16.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.