← back
CVE-2026-55494criticalCWE-284

Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unset

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 0.6%
from disclosure to weapon0 days
Published on NVDSep 30
1st PoCJul 13
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns successfully if Config.AGENT_SECRET is empty. This causes protected Agent APIs to become accessible without authentication. This issue has been patched in version 1.30.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Quenary · tugtainer
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.