Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-18255
Red Hat Red Hat Quay 3.10 — Quay: quay: global read-only superuser can view robot account tokens
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H H H 7.2 .0075 53.4 —
AFFECTED
Product Versions Fixed
Red Hat Quay 3.10 unspecified 1788561841
Red Hat Quay 3.12 unspecified 1788594376
Red Hat Quay 3.14 unspecified 1788593843
Red Hat Quay 3.15 unspecified 1788191755
Red Hat Quay 3.16 unspecified 1789563753
Red Hat Quay 3.17 unspecified 1790690298
Red Hat Quay 3.9 unspecified 1788595574
TIMELINE
Jul 29 Reserved by redhat
Jul 29 Published (CNA: redhat)
Sep 3 PATCH SHIPPED — CVE-2026-18255 (Red Hat Quay 3.15). Fixed in Red Hat Quay 3.15 1788191755.
Description
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 29, 2026 | Reserved | Reserved by redhat |
| July 29, 2026 | Published | Published (CNA: redhat) |
| September 3, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-18255 (Red Hat Quay 3.15). Fixed in Red Hat Quay 3.15 1788191755. |
Affected
Affected products and packages — 7 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Quay 3.10 | — | — | 1788561841 |
| Red Hat | Red Hat Quay 3.12 | — | — | 1788594376 |
| Red Hat | Red Hat Quay 3.14 | — | — | 1788593843 |
| Red Hat | Red Hat Quay 3.15 | — | — | 1788191755 |
| Red Hat | Red Hat Quay 3.16 | — | — | 1789563753 |
| Red Hat | Red Hat Quay 3.17 | — | — | 1790690298 |
| Red Hat | Red Hat Quay 3.9 | — | — | 1788595574 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-18255 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.