boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-18255

Red Hat Red Hat Quay 3.10 — Quay: quay: global read-only superuser can view robot account tokens
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0075   53.4     —
AFFECTED
  Product            Versions     Fixed
  Red Hat Quay 3.10  unspecified  1788561841
  Red Hat Quay 3.12  unspecified  1788594376
  Red Hat Quay 3.14  unspecified  1788593843
  Red Hat Quay 3.15  unspecified  1788191755
  Red Hat Quay 3.16  unspecified  1789563753
  Red Hat Quay 3.17  unspecified  1790690298
  Red Hat Quay 3.9   unspecified  1788595574
TIMELINE
  Jul 29  Reserved by redhat
  Jul 29  Published (CNA: redhat)
  Sep 3   PATCH SHIPPED — CVE-2026-18255 (Red Hat Quay 3.15). Fixed in Red Hat Quay 3.15 1788191755.
CWE-863 · CNA: redhat · CVSS v3.1 · 9 references · NVD status: Awaiting Analysis

Description

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
July 29, 2026ReservedReserved by redhat
July 29, 2026PublishedPublished (CNA: redhat)
September 3, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-18255 (Red Hat Quay 3.15). Fixed in Red Hat Quay 3.15 1788191755.

Affected

Affected products and packages — 7 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red HatRed Hat Quay 3.10——1788561841
Red HatRed Hat Quay 3.12——1788594376
Red HatRed Hat Quay 3.14——1788593843
Red HatRed Hat Quay 3.15——1788191755
Red HatRed Hat Quay 3.16——1789563753
Red HatRed Hat Quay 3.17——1790690298
Red HatRed Hat Quay 3.9——1788595574

Weaknesses

CWE-863

References (9)

Related

Authoritative record: CVE-2026-18255 at cve.org

Vendors: red hat

Weaknesses: CWE-863

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-18255 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.