A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations.
Metrics
Affected Vendors & Products
References
History
Sat, 15 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 14 Aug 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from the same identity provider to bypass configured security restrictions. This bypass could lead to unauthorized access by circumventing intended audience, subject, or authorized-client limitations. | |
| Title | Quay: jwt claim validation bypasses in quay federated robot and sso authentication | |
| First Time appeared |
Redhat
Redhat openshift Update Service Redhat quay |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:/a:redhat:openshift_update_service:5 cpe:/a:redhat:quay:3 |
|
| Vendors & Products |
Redhat
Redhat openshift Update Service Redhat quay |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-14T22:43:01.103Z
Reserved: 2026-08-14T19:46:37.190Z
Link: CVE-2026-74240
No data.
Status : Received
Published: 2026-08-14T23:16:33.960
Modified: 2026-08-14T23:16:33.960
Link: CVE-2026-74240
OpenCVE Enrichment
Updated: 2026-08-15T01:00:10Z