CVE-2026-61833
8.1 HIGHpublic exploit availablePublished 2026-09-18 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the push action, so DELETE requests are not checked for the distinct delete permission. Bearer-authenticated requests also bypass the fine-grained DistSpecAuthzHandler path in pkg/api/authz.go, while DeleteManifest and DeleteBlob perform no independent delete-permission check. A remote attacker with a bearer token limited to pull and push actions can therefore delete manifests and blobs within the token's repository scope, making images unavailable and allowing repository history to be altered despite the token lacking delete authorization. This issue is fixed in version 2.1.18.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weaknesses
CWE-285
Public exploit & PoC references
- https://github.com/project-zot/zot/commit/7bb211bcd4352b90f3e99752607fbd1f050bf7ca
- https://github.com/project-zot/zot/pull/4161
- https://github.com/project-zot/zot/releases/tag/v2.1.18
- https://github.com/project-zot/zot/security/advisories/GHSA-qg67-7m6v-qg25
- https://github.com/project-zot/zot/security/advisories/GHSA-qg67-7m6v-qg25
All references
- https://github.com/project-zot/zot/commit/7bb211bcd4352b90f3e99752607fbd1f050bf7ca
- https://github.com/project-zot/zot/pull/4161
- https://github.com/project-zot/zot/releases/tag/v2.1.18
- https://github.com/project-zot/zot/security/advisories/GHSA-qg67-7m6v-qg25
- https://github.com/project-zot/zot/security/advisories/GHSA-qg67-7m6v-qg25
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2025-71426PoC
- HIGHCVE-2026-10030
- MEDIUMCVE-2026-100878PoC
- HIGHCVE-2026-100885PoC
- MEDIUMCVE-2026-100897
- MEDIUMCVE-2026-101006
- MEDIUMCVE-2026-102261PoC
- HIGHCVE-2026-102293PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.