Vulnerability Description
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to trigger test notifications for another repository. This could lead to unauthorized information disclosure and potential misuse of notification services.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift Update Service | - |
| Redhat | Quay | 3.0.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-74242Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516140Issue TrackingVendor Advisory
FAQ
What is CVE-2026-74242?
CVE-2026-74242 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, incl...
How severe is CVE-2026-74242?
CVE-2026-74242 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-74242?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openshift Update Service, Redhat Quay.