Server-Side Template Injection in Tugtainer by Quenary
CVE-2026-47752

9.9CRITICAL

Key Information:

Vendor

Quenary

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-47752?

Tugtainer, a self-hosted application designed for automating Docker container updates, is affected by a Server-Side Template Injection (SSTI) vulnerability. This issue arises from the notification template rendering, which utilizes an unsandboxed jinja2.Environment. Consequently, any authenticated user can exploit this to execute arbitrary operating system commands with root privileges inside the affected Docker container. This vulnerability exists in versions prior to 1.30.2, which resolves the issue and enhances security.

Affected Version(s)

tugtainer < 1.30.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.