CVE-2025-4374
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they
CVSS
6.5
Medio
EPSS
0.3%
p25
KEV
—
Exploit Today
8
0-100
Publicado: 6 may 2025 · Última mod.: 7 ago 2026 · CWE-266
0.3%EPSS · 30 días0.3%
2026-08-172026-09-13
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
- access.redhat.comhttps://access.redhat.com/errata/RHBA-2025:8262
- access.redhat.comhttps://access.redhat.com/errata/RHBA-2025:8263
- access.redhat.comhttps://access.redhat.com/errata/RHBA-2025:8687
- access.redhat.comhttps://access.redhat.com/errata/RHBA-2025:8688
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2025-4374
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2364267
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-908567.3 ALT—
———A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.8hCVE-2026-908516.3 MED—
———A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been published and may be used.9hCVE-2026-908124.3 MED—
———A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.15hCVE-2026-908106.3 MED—
———A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.15hCVE-2026-868307.2 ALT—
———Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment.
This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.15hCVE-2026-907877.3 ALT—
———A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.15h