Data Exposure Vulnerability in Red Hat Quay
CVE-2026-74242

5.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
14 August 2026

What is CVE-2026-74242?

A flaw exists in Red Hat Quay that permits an administrator with knowledge of a notification's Universally Unique Identifier (UUID) to access the notification configuration. This includes the ability to view sensitive information such as webhook URLs, Slack tokens, and email addresses. Additionally, this vulnerability enables the administrator to trigger test notifications for other repositories, which may result in unauthorized information disclosure and potential misuse of notification services.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank meifukun (https://github.com/meifukun) for reporting this issue.
.