CVE-2026-105447: Quay: quay: global read-only superuser can access build trigger write credentials

Published Oct 5, 2026
·
Updated

A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to retrieve these delegate tokens. This issue allows a restricted user to bypass read-only limitations and push arbitrary container images to private repositories, leading to privilege escalation.

Other sources

A flaw was found in Quay's build trigger API endpoints. The BuildTriggerList.get and BuildTrigger.get handlers in endpoints/api/trigger.py hardcode canadmin=True when serializing trigger data via the triggerview function, regardless of whether the caller is a full administrator or a global read-only superuser. This causes the trigger configuration, including delegate write tokens embedded in webhook endpoint URLs, to be exposed to users in the GLOBALREADONLYSUPERUSERS list. These delegate tokens carry push scope for the repository and can be used to push arbitrary container images to private repositories, bypassing the read-only restriction of the caller's role.

— Red Hat

Affected Software

1 affected component
Red Hat Quay

Event History

Oct 5, 2026
Data Sourced
via Red Hat·01:56 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·08:29 PM
Data Sourced
via MITRE·08:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user configured as a global read-only superuser can exploit it. The user must be able to query the build trigger API for a repository with a build trigger.

2

What access can an attacker gain through the exposed data?

The API response can expose delegate write tokens embedded in build-trigger webhook endpoint URLs. Those tokens have push scope for the affected repository and can be used to push arbitrary container images to private repositories.

3

How can administrators determine whether a user may have been exposed to this issue?

Review membership in the GLOBAL_READONLY_SUPER_USERS list and identify which of those users could query build trigger API endpoints. Repositories with build triggers are relevant because their trigger configuration can contain the delegate write tokens.

4

What should be prioritized if immediate remediation is not available?

Prioritize restricting global read-only superuser access to build trigger API data and protecting or rotating delegate write tokens associated with build triggers where possible. Treat tokens from potentially exposed trigger configurations as repository write credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203