CVE-2026-103868

MEDIUM CVSS 3.1: 6.5 EPSS 0.23%
Updated Oct 07, 2026
Red Hat
Parameter Value
CVSS 6.5 (MEDIUM)
Type CWE-488
Vendor Red Hat
Public PoC No

A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry.

Content stored in Pulp is not changed, and the service is not stopped.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat satellite 6 red hat:red hat ansible automation platform 2 red hat:red hat update infrastructure 5 red hat:red hat update infrastructure 4 for cloud providers