CRITICAL 9.8 NVD
CVE-2026-55494
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker man
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns successfully if Config.AGENT_SECRET is empty. This causes protected Agent APIs to become accessible without authentication. This issue has been patched in version 1.30.4.
References
- https://github.com/Quenary/tugtainer/commit/0052a5544e187a4d12f771838a8a23ca4afb61cd
- https://github.com/Quenary/tugtainer/releases/tag/v1.30.4
- https://github.com/Quenary/tugtainer/security/advisories/GHSA-wgw2-c96g-p7h7
- https://github.com/Quenary/tugtainer/security/advisories/GHSA-wgw2-c96g-p7h7
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-30 via NVD.
Risk Timeline
CVE Disclosed2026-09-30 · -1 days ago
Remediation Resources
vulnfeed aggregates 9504 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.