Information Disclosure Vulnerability in Red Hat Quay's Exported Logs Feature
CVE-2026-74245

5.9MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
14 August 2026

What is CVE-2026-74245?

A vulnerability has been identified in Red Hat Quay's exported logs feature that allows an unauthenticated attacker to download action logs using a valid file ID. Despite the complexity of file IDs, they can be extracted from unprotected communication channels, such as plaintext emails and webhook callbacks. The exploitation of this flaw could lead to the unauthorized exposure of sensitive information, including usernames, email addresses, IP addresses, and action-specific metadata. Organizations using this product should review their logging configurations and implement measures to secure file IDs against interception.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank meifukun (https://github.com/meifukun) for reporting this issue.
.