← Vulnerability feed

Vulnerability record · CVE-2026-74245 · published 14 August 2026

CVE-2026-74245: Redhat openshift update service missing authentication for critical function vulnerability

Redhat · Openshift Update Service

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure, potentially exposing sensitive data such as usernames, email addresses, IP addresses, and action-specific metadata.

7.5 CVSS 3.1 High EPSS 0.42% · top 66.4% CWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
20 Aug 2026Last modified by NVD

Description

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure, potentially exposing sensitive data such as usernames, email addresses, IP addresses, and action-specific metadata.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-74245 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2021-3762Redhat clair path traversal vulnerabilityA directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w…EPSS 4.8%9.0CVE-2020-27832Redhat quay cross-site scripting vulnerabilityA flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. Thi…EPSS 0.91%8.8CVE-2026-32590Redhat mirror registry for red hat openshift deserialization of untrusted data vulnerabilityA flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u…EPSS 0.79%8.8CVE-2022-1227Podman project podman improper privilege management vulnerabilityA privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is d…EPSS 4.2%8.8CVE-2019-3864Redhat quay cross-site request forgery vulnerabilityA vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which i…EPSS 0.44%8.2CVE-2026-74243Redhat openshift update service missing authentication for critical function vulnerabilityA flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST reque…EPSS 0.46%8.1CVE-2026-6848Redhat quay insufficient session expiration vulnerabilityA flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot acc…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2026-74245), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.