CVE-2026-55181
Received Received - Intake

Authentication Bypass in Tugtainer via OIDC Login Endpoint

Vulnerability report for CVE-2026-55181, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects the user to the configured OIDC authorization endpoint. This bypasses the intended OIDC disable switch. This issue has been patched in version 1.30.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
quenary tugtainer to 1.30.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Tugtainer is a self-hosted app for automating Docker container updates. This vulnerability allows OIDC authentication to be initiated even when OIDC is explicitly disabled via configuration. While the system correctly reports OIDC as disabled at the /auth/oidc/enabled endpoint, a direct request to /auth/oidc/login bypasses this check and triggers the OIDC login flow anyway.

Detection Guidance

To detect this vulnerability, check if requests to /auth/oidc/login return HTTP 302 redirects even when OIDC is disabled. Use curl to test the endpoint: curl -v http://<tugtainer-host>/auth/oidc/login. If OIDC is disabled but you receive a redirect to an OIDC provider, the system is vulnerable.

Impact Analysis

This vulnerability enables users to bypass intended authentication restrictions. If OIDC was disabled to limit access, attackers could still initiate OIDC login flows, potentially gaining unauthorized access to the system. The flaw allows authentication attempts using disabled providers to proceed, creating a security bypass.

Mitigation Strategies

Immediately upgrade Tugtainer to version 1.30.3 or later. Verify the fix by testing the /auth/oidc/login endpoint again. Ensure OIDC is properly disabled by checking the /auth/oidc/enabled endpoint returns false. Review authentication logs for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55181. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart