PT-2026-95512 · Zot · Zot
CVE-2026-61833
·
Published
2026-09-18
·
Updated
2026-09-28
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
zot versions prior to 2.1.18
Description
A flaw in the bearer authentication handler allows a remote attacker with a token limited to
pull and push actions to delete manifests and blobs within the token's repository scope. This occurs because the handler in pkg/api/authn.go maps all HTTP methods except GET and HEAD to the push action, failing to verify the distinct delete permission for DELETE requests. Additionally, bearer-authenticated requests bypass the DistSpecAuthzHandler in pkg/api/authz.go, and the DeleteManifest() and DeleteBlob() functions do not perform independent authorization checks. This can lead to unauthorized deletion of production images and the alteration of repository history.Recommendations
Update zot to version 2.1.18.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zot