PT-2026-103470 · Tugtainer · Tugtainer
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tugtainer versions prior to 1.30.4
Description
Tugtainer Agent allows unauthenticated access to Docker management APIs when the
AGENT SECRET is not configured. The system uses request signatures to protect API routes, but the signature verification function in agent/auth.py returns successfully if Config.AGENT SECRET is empty, bypassing authentication for protected Agent APIs.Recommendations
Update to version 1.30.4.
Configure the
AGENT SECRET variable to ensure API routes are protected by signature verification.Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tugtainer