THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18255 (HIGH 7.2) — A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.

[NVD] CVE-2026-18255 (HIGH 7.2) — A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.

lownvdPublished 2026-07-29

CVE-2026-18255 CVSS: 7.2 HIGH Published: 2026-07-29T17:16:51.393

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18255