OIDC Login Flaw in Tugtainer Affects User Authentication Process
CVE-2026-87004

8.1HIGH

Key Information:

Vendor

Quenary

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-87004?

Tugtainer, an application for automating updates of Docker containers, had a significant flaw in its OIDC login flow prior to version 1.31.3. The vulnerability arose when the application decoded the id_token using an insecure method that bypassed crucial security checks, including signature verification and audience validation. This oversight allowed the extracted claims to be used directly as user identifiers without adequate verification, potentially leading to unauthorized access. The issue was addressed in version 1.31.3, which implements proper checks to reinforce the integrity of user sessions.

Affected Version(s)

tugtainer < 1.31.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.