CVE-2026-87004
Received Received - Intake

OIDC Token Signature Bypass in Tugtainer

Vulnerability report for CVE-2026-87004, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
quenary tugtainer 1.31.3
quenary tugtainer to 1.31.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87004 affects Tugtainer versions before 1.31.3. It involves improper handling of OIDC login tokens where the backend decodes tokens without verifying signatures, audience, issuer, or expiration. This allows attackers to forge tokens and impersonate users.

Detection Guidance

To detect this vulnerability, check if your Tugtainer instance is running a version prior to 1.31.3. Run: docker ps --format '{{.Image}}' | grep tugtainer. If the version is <=1.31.2, the system is vulnerable. Inspect logs for OIDC login attempts to see if tokens are processed without proper validation.

Impact Analysis

An attacker could bypass authentication, gain unauthorized access to the API, and impersonate any user. This could lead to data breaches, unauthorized actions, or full system compromise if exploited via man-in-the-middle attacks or a compromised OIDC provider.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It undermines authentication controls, potentially resulting in non-compliance with data protection and security standards.

Mitigation Strategies

Upgrade Tugtainer to version 1.31.3 or later immediately. Ensure OIDC tokens are validated with jwt.decode() including signature, audience, issuer, and expiry checks. Configure allowlists via OIDC_ALLOWED_EMAILS or OIDC_ALLOWED_SUBJECTS if needed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87004. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart