OIDC Login Flaw in Tugtainer Affects User Authentication Process
CVE-2026-87004
8.1HIGH
What is CVE-2026-87004?
Tugtainer, an application for automating updates of Docker containers, had a significant flaw in its OIDC login flow prior to version 1.31.3. The vulnerability arose when the application decoded the id_token using an insecure method that bypassed crucial security checks, including signature verification and audience validation. This oversight allowed the extracted claims to be used directly as user identifiers without adequate verification, potentially leading to unauthorized access. The issue was addressed in version 1.31.3, which implements proper checks to reinforce the integrity of user sessions.
Affected Version(s)
tugtainer < 1.31.3
