Authenticated Server-Side Request Forgery in Tugtainer by Quenary
CVE-2026-62308

9.1CRITICAL

Key Information:

Vendor

Quenary

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-62308?

Tugtainer, a self-hosted app designed for automating Docker container updates, prior to version 1.30.6, contains a vulnerability that allows authenticated users to exploit the /settings/test_notification endpoint. This endpoint directly processes arbitrary user-supplied URLs without restrictions on protocols, hostnames, or IP ranges, leading to potential malicious outbound HTTP requests. This behavior can be exploited as an authenticated blind SSRF, which could allow attackers to access sensitive internal services or perform actions on behalf of the server. An update has been made available with version 1.30.6, which addresses this issue.

Affected Version(s)

tugtainer < 1.30.6

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.