漏洞概述 漏洞编号: CVE-2026-18255 漏洞标题: Global read-only superuser can view robot account tokens 状态: NEW 产品: Security Response 组件: vulnerability 优先级: high 严重程度: high 目标里程碑: --- 指派给: Product Security 报告时间: 2026-07-29 15:52 UTC by OSIDB Bzimport 修改时间: 2026-07-29 16:25 UTC 影响范围 影响描述: Read-only administrative users can perform actions beyond intended scope. Robot account tokens are persistent by default (they do not expire), and depending on configuration can grant read (pull), write (push), or admin level access to container image repositories. 影响细节: 只读管理员用户可以执行超出预期范围的操作。机器人账户令牌默认是持久的(不会过期),并且根据配置可以授予容器镜像仓库的读取(拉取)、写入(推送)或管理员级别访问权限。 修复方案 修复版本: 未指定 克隆: 未指定 环境: 未指定 最后关闭: 未指定 Embargoed: 未指定 复现步骤 1. Configure a user in GLOBAL_READONLY_SUPER_USERS only. 2. Confirm the same user is not present in SUPER_USERS. 3. Apply config and allow Quay/operator reconciliation. 4. Log in as that user. 5. Navigate to robot account management and token views for a repo they are not a member of. 6. Observe that token visibility is allowed. 代码块 其他信息 依赖项: depends on / blocked 附件: (Terms of Use) 备注: You need to log in before you can comment on or make changes to this bug.