PT-2026-3491 · Tugtainer · Tugtainer

·

CVE-2026-23846

·

Published

2026-01-19

·

Updated

2026-01-20

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tugtainer versions prior to 1.16.1
Description Tugtainer is a self-hosted application designed for automating updates of Docker containers. Prior to version 1.16.1, the password authentication process transmits passwords through URL query parameters rather than utilizing the HTTP request body. This practice results in passwords being recorded in server access logs and potentially exposed via browser history, Referer headers, and proxy logs.
Recommendations Update Tugtainer to version 1.16.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23846
GHSA-F2QF-F544-XM4P

Affected Products

Tugtainer