REDHAT-BUG-2460119: Medium severity Red Hat Quay vulnerability

Published Apr 21, 2026
·
Updated

A flaw was found in Red Hat Quay. When Quay requests password re-verification for sensitive operations (e.g., token generation, robot account creation) due to session timeout, the re-authentication prompt can be bypassed. Although the UI displays an error popup for invalid credentials, the sensitive operations are still successfully executed in the background. This allows a user whose session has timed out (or an attacker with access to an idle authenticated browser session) to perform privileged actions without providing valid credentials.

The vulnerability exists in both the old and new Quay UI. Some endpoints that require fresh authentication are affected (e.g., robot account creation, token generation) while others correctly enforce reauthentication (e.g., user creation).

Upstream reference: PROJQUAY-11274

Affected Software

1 affected component
Red Hat Quay

Event History

Apr 21, 2026
Data Sourced
via Red Hat·02:31 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2460119?

The severity of REDHAT-BUG-2460119 is considered high due to potential unauthorized access to sensitive operations.

2

How do I fix REDHAT-BUG-2460119?

To fix REDHAT-BUG-2460119, ensure you are using the latest patched version of Red Hat Quay as released by Red Hat.

3

What operations are affected by the vulnerability in REDHAT-BUG-2460119?

Sensitive operations such as token generation and robot account creation are affected by the vulnerability in REDHAT-BUG-2460119.

4

Can the password re-verification bypass in REDHAT-BUG-2460119 be exploited?

Yes, the password re-verification bypass in REDHAT-BUG-2460119 can be exploited to perform sensitive actions without proper authentication.

5

What can I do if I am using an affected version of Red Hat Quay regarding REDHAT-BUG-2460119?

If you are using an affected version of Red Hat Quay regarding REDHAT-BUG-2460119, you should promptly upgrade to the latest secure version as recommended by Red Hat.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203