PT-2026-95512 · Zot · Zot

CVE-2026-61833

·

Published

2026-09-18

·

Updated

2026-09-28

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions zot versions prior to 2.1.18
Description A flaw in the bearer authentication handler allows a remote attacker with a token limited to pull and push actions to delete manifests and blobs within the token's repository scope. This occurs because the handler in pkg/api/authn.go maps all HTTP methods except GET and HEAD to the push action, failing to verify the distinct delete permission for DELETE requests. Additionally, bearer-authenticated requests bypass the DistSpecAuthzHandler in pkg/api/authz.go, and the DeleteManifest() and DeleteBlob() functions do not perform independent authorization checks. This can lead to unauthorized deletion of production images and the alteration of repository history.
Recommendations Update zot to version 2.1.18.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61833
GHSA-QG67-7M6V-QG25
GO-2026-6527

Affected Products

Zot