CVE-2026-103868
Received Received - Intake

Pulp-container Credential Reuse in Registry Authentication

Vulnerability report for CVE-2026-103868, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry. Content stored in Pulp is not changed, and the service is not stopped.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat pulp-container 1.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-488 The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103868 is a flaw in Red Hat's pulp-container software where registry credentials (username, password, or bearer token) from one authenticated container remote are incorrectly reused for subsequent downloads in the same worker process. This happens because credentials are cached process-wide across Pulp domains until the worker exits. An attacker with sync permissions who points a remote to a malicious server they control can extract credentials intended for a different remote.

Detection Guidance

Monitor Pulp worker processes for unexpected credential reuse by checking logs for sync operations from untrusted remotes. Inspect pulp-container worker logs for multiple sync tasks using the same credentials across different remotes.

Impact Analysis

An attacker could gain access to credentials for other container remotes, potentially allowing them to access or manipulate container images in upstream registries. This requires the attacker to have sync permissions and modify the remote URL. The impact is limited to confidentiality, as integrity and availability are not affected.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data stored in container images, potentially violating GDPR (data protection) or HIPAA (health information privacy) if such data is exposed. Organizations using pulp-container must ensure credentials are properly managed to maintain compliance.

Mitigation Strategies

Apply available security updates for pulp-container. Avoid syncing authenticated container remotes from untrusted sources. Restart Pulp workers after updates to clear cached credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103868. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart