Database/Control plane, storage & DevOps
Katello: Docker Tags API leaks repository metadata across organization boundaries
Impact
The Docker Tags repositories API does not enforce organization scoping: a user authorized to view products in one organization can supply a tag identifier and read repository metadata belonging to a different organization. On a Satellite or Katello instance that serves as the container registry and content source for several teams or customers, the organization boundary is the tenancy boundary, and this punches a read hole in it. What leaks is repository configuration metadata - names, upstream and repo settings - not image content or credentials, so the consequence is reconnaissance into another tenant's software supply chain rather than direct compromise.
Who can reach it
A remote, authenticated Satellite/Katello user holding view-products permission in any one organization. No administrative privilege and no user interaction required.
What to do
Apply the Satellite 6 / Katello update when Red Hat publishes it; this is a service-side package update and restart of the Satellite services, with no change needed on managed hosts. Fixed versions are not stated in this record - track the Red Hat CVE page and Bugzilla 2547765. There is no described workaround short of tightening which accounts hold view-products in multi-organization instances.
References
Related entries
- Grafana: alert rules API returns rules from folders the user cannot readCVE-2026-13719 · Grafana (alert rules API list endpoint, folder authorization)Medium
- GitLab EE: developer-role user can influence the execution environment of Pipeline Execution Policy jobsCVE-2026-15387 · GitLab EE (Pipeline Execution Policy enforcement jobs, job dependency handling)Medium
- GitLab EE: Security Manager role can run arbitrary CI/CD jobs and read protected variablesCVE-2026-16794 · GitLab EE (compliance framework management authorization)Medium
- GitLab EE: authenticated user can view restricted group configuration settingsCVE-2026-18244 · GitLab EE (group settings page authorization)Medium
- GitLab EE: GraphQL query exposes policy configuration from an unauthorized namespaceCVE-2026-18433 · GitLab EE (GraphQL query for namespace policy configuration)Medium
- NetApp ONTAP S3 NAS bucket directory listing: An authenticated S3 user lists the contents of directories they have noCVE-2026-22052 · NetApp ONTAP S3 NAS bucket directory listingMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.