---
id: CVE-2026-18255
title: A flaw was found in Quay
summary: >-
  A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is
  able to view robot account tokens for repositories they are not a member of,
  allowing an attacker with read-only superuser privileges to impersonate any
  robot …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: Red Hat
product: quay/quay-rhel8
affected:
  - quay/quay-rhel8 (all versions)
  - quay/quay-rhel8 (all versions)
  - quay/quay-rhel8 (all versions)
  - quay/quay-rhel8 (all versions)
  - quay/quay-rhel9 (all versions)
  - quay/quay-rhel8 (all versions)
patched:
  - quay 3.15
  - quay 3.9
published: '2026-07-29'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T18:17:11.327'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18255'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:63307'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:65514'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:66084'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:66523'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69255'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70267'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18255'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2508454'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18255.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18255'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18255'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-07-29T18:05:45.459458Z'
epss: 0.00654
epssPercentile: 0.49101
ingestedAt: '2026-09-08T22:12:31.038Z'
---

## Overview

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:63307** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63307)
- **RHSA-2026:65514** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65514)
- **Red Hat VEX** · Important · affected: Red Hat Quay 3 · no fix planned: Red Hat Quay 3 · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18255.json)
- **RHSA-2026:66084** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66084)
- **RHSA-2026:66523** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66523)
- **RHSA-2026:69255** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69255)
- **RHSA-2026:70267** · Red Hat · fixed in: Red Hat Quay 3.14 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70267)
