Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6848

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 5.4
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with access to an idle authenticated browser session, to perform privileged actions without providing valid credentials. The vulnerability enables unauthorized execution of sensitive operations despite the user interface displaying an error for invalid credentials.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00263
Низкий

5.4 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5.4
redhat
4 месяца назад

A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with access to an idle authenticated browser session, to perform privileged actions without providing valid credentials. The vulnerability enables unauthorized execution of sensitive operations despite the user interface displaying an error for invalid credentials.

CVSS3: 5.4
github
3 месяца назад

A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with access to an idle authenticated browser session, to perform privileged actions without providing valid credentials. The vulnerability enables unauthorized execution of sensitive operations despite the user interface displaying an error for invalid credentials.

EPSS

Процентиль: 18%
0.00263
Низкий

5.4 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-613