AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-74240

MEDIUM · CVSS 5.4

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Red Hat Quay's JWT validation for federated robot accounts and SSO authentication is vulnerable due to flaws in audience verification and the enforcement of `azp` and `sub` claims. This could allow an attacker with a validly-signed token from the same identity provider to bypass security restrictions, potentially leading to unauthorized access. Organizations using Red Hat Quay should prioritize addressing this vulnerability to protect against potential exploitation.

CVE
CVE-2026-74240
Severity
MEDIUM
CVSS
5.4
EPSS
N/A

Original NVD Description

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations.