PT-2026-103470 · Tugtainer · Tugtainer

·

CVE-2026-55494

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tugtainer versions prior to 1.30.4
Description Tugtainer Agent allows unauthenticated access to Docker management APIs when the AGENT SECRET is not configured. The system uses request signatures to protect API routes, but the signature verification function in agent/auth.py returns successfully if Config.AGENT SECRET is empty, bypassing authentication for protected Agent APIs.
Recommendations Update to version 1.30.4. Configure the AGENT SECRET variable to ensure API routes are protected by signature verification.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55494
GHSA-WGW2-C96G-P7H7

Affected Products

Tugtainer