๐Ÿ” CVE Alert

CVE-2026-55181

CRITICAL 9.4

Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false

CVSS Score
9.4
EPSS Score
0.0%
EPSS Percentile
0th

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects the user to the configured OIDC authorization endpoint. This bypasses the intended OIDC disable switch. This issue has been patched in version 1.30.3.

CWE CWE-284
Vendor quenary
Product tugtainer
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for quenary tugtainer

Be the first to know when new critical vulnerabilities affecting quenary tugtainer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

Quenary / tugtainer
< 1.30.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Quenary/tugtainer/security/advisories/GHSA-rg7c-vpfp-2w43 github.com: https://github.com/Quenary/tugtainer/commit/76371db679334b002d4af544b0f3b8587ad86f52 github.com: https://github.com/Quenary/tugtainer/releases/tag/v1.30.3