CVE-2026-6848
published 2026-04-22CVE-2026-6848: A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account…
PriorityP352high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.26%
17.8th percentile
A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with access to an idle authenticated browser session, to perform privileged actions without providing valid credentials. The vulnerability enables unauthorized execution of sensitive operations despite the user interface displaying an error for invalid credentials.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| quay | quay-rhel8 | — | — |
| quay | quay-rhel9 | — | — |
| redhat | quay | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Red Hat Quay 3 User Interface session expiration
vuldb·2026-05-21·CVSS 8.1
CVE-2026-6848 [HIGH] Red Hat Quay 3 User Interface session expiration
A vulnerability described as critical has been identified in Red Hat Quay 3. Affected by this issue is some unknown functionality of the component User Interface. Such manipulation leads to session expiration.
This vulnerability is uniquely identified as CVE-2026-6848. The attack can be launched remotely. No exploit exists.
GHSA
GHSA-fwq2-5p9g-fm29: A flaw was found in Red Hat Quay
ghsa_unreviewed·2026-04-22
CVE-2026-6848 [MEDIUM] CWE-613 GHSA-fwq2-5p9g-fm29: A flaw was found in Red Hat Quay
A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with access to an idle authenticated browser session, to perform privileged actions without providing valid credentials. The vulnerability enables unauthorized execution of sensitive operations despite the user interface displaying an error for invalid credentials.
Red Hat
quay: Red Hat Quay: Authentication bypass allows privileged actions without valid credentials
vendor_redhat·2026-04-10·CVSS 5.4
CVE-2026-6848 [MEDIUM] CWE-613 quay: Red Hat Quay: Authentication bypass allows privileged actions without valid credentials
quay: Red Hat Quay: Authentication bypass allows privileged actions without valid credentials
A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with access to an idle authenticated browser session, to perform privileged actions without providing valid credentials. The vulnerability enables unauthorized execution of sensitive operations despite the user interface displaying an error for invalid credentials.
Statement: This Moderate impact flaw in Red Hat Quay allows an attacker with access to an idle authenticated browser session to bypass session reauthentication. This en
No detection rules found.
No public exploits indexed.
2026-04-22
Published