{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-105447",
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "state": "PUBLISHED",
        "assignerShortName": "redhat",
        "dateReserved": "2026-10-05T13:52:15.828Z",
        "datePublished": "2026-10-05T20:29:45.881Z",
        "dateUpdated": "2026-10-05T20:29:45.881Z"
    },
    "containers": {
        "cna": {
            "title": "Quay: quay: global read-only superuser can access build trigger write credentials",
            "metrics": [
                {
                    "other": {
                        "content": {
                            "value": "Moderate",
                            "namespace": "https://access.redhat.com/security/updates/classification/"
                        },
                        "type": "Red Hat severity rating"
                    }
                },
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "NONE",
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "confidentialityImpact": "LOW",
                        "integrityImpact": "HIGH",
                        "privilegesRequired": "HIGH",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "format": "CVSS"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to retrieve these delegate tokens. This issue allows a restricted user to bypass read-only limitations and push arbitrary container images to private repositories, leading to privilege escalation."
                }
            ],
            "affected": [
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Quay 3",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "quay/quay-rhel8",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:quay:3"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Quay 3",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "quay/quay-rhel9",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:quay:3"
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://access.redhat.com/security/cve/CVE-2026-105447",
                    "tags": [
                        "vdb-entry",
                        "x_refsource_REDHAT"
                    ]
                },
                {
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545916",
                    "name": "RHBZ#2545916",
                    "tags": [
                        "issue-tracking",
                        "x_refsource_REDHAT"
                    ]
                }
            ],
            "datePublic": "2026-09-30T00:00:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-863",
                            "description": "Incorrect Authorization",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "x_redhatCweChain": "CWE-863: Incorrect Authorization",
            "workarounds": [
                {
                    "lang": "en",
                    "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."
                }
            ],
            "timeline": [
                {
                    "lang": "en",
                    "time": "2026-09-30T00:00:00.000Z",
                    "value": "Reported to Red Hat."
                },
                {
                    "lang": "en",
                    "time": "2026-09-30T00:00:00.000Z",
                    "value": "Made public."
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Red Hat would like to thank Shashank (CredShields) for reporting this issue."
                }
            ],
            "providerMetadata": {
                "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
                "shortName": "redhat",
                "dateUpdated": "2026-10-05T20:29:45.881Z"
            },
            "x_generator": {
                "engine": "cvelib 1.8.0"
            }
        }
    }
}