Red Hat Quay Authentication Bypass Vulnerability Allowing Privileged Actions

Vulnerability

An authentication bypass vulnerability has been identified in Red Hat Quay versions 3.9 through 3.17. This flaw allows users with timed-out sessions, or attackers with access to idle authenticated browser sessions, to bypass re-authentication prompts for sensitive operations such as token generation and robot account creation. Although the user interface indicates an error for invalid credentials, the operations are still executed in the background, enabling unauthorized access to privileged functions.

Impact

Exploiting this vulnerability allows for unauthorized execution of sensitive operations, such as generating tokens or creating robot accounts, without valid credentials. This could lead to unauthorized access or actions being performed on behalf of the user.

Reproduction

The vulnerability can be reproduced by initiating a sensitive operation that requires re-authentication, such as creating a robot account or generating a token, after the session has timed out. The re-authentication prompt can be ignored, and the operation will still be completed successfully, despite the user interface displaying an error for invalid credentials.

Added: Apr 22, 2026, 11:13 AM
Updated: Apr 22, 2026, 11:13 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
5.2
remediation
0.0
relevance
6.5
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.