CVE-2026-107444
Received Received - Intake

Katello Docker Tags API Organization Scope Bypass

Vulnerability report for CVE-2026-107444, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: redhat-SADP

Description

A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat katello *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107444 is a flaw in Katello's Docker Tags repositories API where organization scoping is not enforced. An authenticated user with view_products permission in one organization can access repository metadata from another organization by providing a Docker tag identifier. This allows unauthorized disclosure of repository configuration details across organization boundaries.

Detection Guidance

To detect this vulnerability, check Katello logs for unauthorized access attempts to Docker Tags repositories API endpoints. Look for requests with tag identifiers but missing organization filters. Review API access logs for users querying repositories outside their assigned organization.

Impact Analysis

This vulnerability could allow an attacker with limited access to view sensitive repository metadata from other organizations. While it does not directly modify data or disrupt services, it may expose configuration details like repository names, product associations, content types, and upstream URLs, potentially aiding further attacks.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict data isolation between organizations or entities, such as GDPR's data protection principles or HIPAA's access controls. Unauthorized access to repository metadata may constitute a breach of confidentiality obligations.

Mitigation Strategies

Apply the latest Katello updates immediately. Restrict API access to authenticated users with minimal required permissions. Monitor API endpoints for suspicious queries involving Docker tag identifiers. Consider disabling the Docker Tags repositories API if not essential.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107444. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart