Container Image Registry Vulnerability in Zot by Project Zot
CVE-2026-61833

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-61833?

A vulnerability exists in Zot, a container image and artifact registry, where the bearer authentication handler does not properly enforce delete permissions. Specifically, DELETE requests are mistakenly treated like push actions due to improper mapping, allowing unauthorized users possessing a bearer token to delete manifests and blobs from a repository. This flaw compromises the integrity of image availability and repository history. The issue has been addressed in version 2.1.18.

Affected Version(s)

zot < 2.1.18

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.