CVE-2026-55494
Received Received - Intake

Unauthenticated API Access in Tugtainer Agent

Vulnerability report for CVE-2026-55494, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns successfully if Config.AGENT_SECRET is empty. This causes protected Agent APIs to become accessible without authentication. This issue has been patched in version 1.30.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
quenary tugtainer to 1.30.4 (exc)
quenary tugtainer 1.30.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55494 is a critical vulnerability in Tugtainer Agent, a Docker management tool. It allows unauthenticated access to Docker management APIs if the AGENT_SECRET environment variable is not set. The issue occurs because the signature verification function in agent/auth.py returns success without checking signatures when AGENT_SECRET is empty, exposing sensitive Docker APIs to attackers.

Detection Guidance

Check if Tugtainer Agent is running without AGENT_SECRET configured by inspecting environment variables and Docker container settings. Look for exposed Docker API endpoints on the Tugtainer Agent port.

Impact Analysis

This vulnerability allows attackers to interact with Docker APIs without authentication. They could list, create, stop, or remove containers, pull images, and access logs. This could lead to unauthorized control over container environments, data theft, or disruption of services if the Tugtainer Agent is exposed to untrusted networks.

Mitigation Strategies
  • Update Tugtainer Agent to version 1.30.4 or later.
  • Set a strong AGENT_SECRET environment variable for the Tugtainer Agent container.
  • Restart the Tugtainer Agent service after applying changes.
  • Ensure no unauthenticated Docker API access is permitted in network configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55494. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart