PT-2026-3491 · Tugtainer · Tugtainer

Thxtech

·

Published

2026-01-19

·

Updated

2026-01-20

·

CVE-2026-23846

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tugtainer versions prior to 1.16.1
Description Tugtainer is a self-hosted application designed for automating updates of Docker containers. Prior to version 1.16.1, the password authentication process transmits passwords through URL query parameters rather than utilizing the HTTP request body. This practice results in passwords being recorded in server access logs and potentially exposed via browser history, Referer headers, and proxy logs.
Recommendations Update Tugtainer to version 1.16.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-23846
GHSA-F2QF-F544-XM4P

Affected Products

Tugtainer