CVE-2026-23846
Last modified
CVE-2026-23846 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to be logged in server access logs and potentially exposed through browser history, Referer headers, and proxy logs. Version 1.16.1 patches the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Quenary | Tugtainer | < 1.16.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-23846?
How severe is CVE-2026-23846?
How do I fix CVE-2026-23846?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23840Movary is a web application to track, rate and explore your …6.1
- CVE-2026-23841Movary is a web application to track, rate and explore your …6.1
- CVE-2026-23842ChatterBot is a machine learning, conversational dialog engi…7.5
- CVE-2026-23843teklifolustur_app is a web-based PHP application that allows…7.1
- CVE-2026-23844Whisper Money is a personal finance application. Versions pr…4.3
- CVE-2026-23845Mailpit is an email testing tool and API for developers. Ver…7.5
- CVE-2026-23847SiYuan is a personal knowledge management system. Versions p…6.1
- CVE-2026-23848MyTube is a self-hosted downloader and player for several vi…5.3
- CVE-2026-23849File Browser provides a file managing interface within a spe…5.3
- CVE-2026-2385The The Plus Addons for Elementor – Addons for Elementor, Pa…5.3
- CVE-2026-23850SiYuan is a personal knowledge management system. In version…7.5
- CVE-2026-23851SiYuan is a personal knowledge management system. Versions p…6.5
Are you affected by CVE-2026-23846?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
