External risk intelligence

Tugtainer OIDC Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-55181

Tugtainer is a self-hosted container management tool. While such tools often run in internal environments, they may be exposed to the internet depending on the specific deployment configuration chosen by the user. The vulnerability involves an authentication endpoint reachable via network requests, making it plausibly accessible if the service is not restricted to a local or VPN-only network.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in Tugtainer, a self-hosted application for automating Docker container updates, that could allow unauthenticated access to authentication flows even when the feature is intended to be disabled. This bypasses a security control designed to prevent unauthorized access.

  • Authentication bypass allows unauthorized access.
  • Matters if OIDC is disabled but still accessible.
  • Confirm if disabled OIDC is still exposed.

Attack Path

How an attacker could exploit the issue

An attacker could bypass Tugtainer's intended authentication settings by sending a direct request to a login endpoint, even when that feature is supposed to be disabled. This would allow them to initiate a potentially unauthorized login flow, which could lead to compromised data or unauthorized actions.

  • No authentication required.
  • Direct login request triggers flow.
  • Data exposure and unauthorized actions.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to bypass authentication controls when OIDC is intended to be disabled, potentially leading to unauthorized access to Tugtainer's functionalities.

  • Unauthorized access to Tugtainer.
  • Authentication bypass through direct login request.
  • Compromised container update automation.

Operational Fix

Recommended remediation, mitigation, and detection steps

Self-hosted applications like Tugtainer require careful ownership assessment. Typically, the platform or infrastructure team responsible for deploying and managing container orchestration systems would be accountable. Their first step should be to identify all instances of Tugtainer within the environment, confirm network accessibility and business criticality, and then assign an owner for remediation planning.

  • Platform or infrastructure team owns.
  • Verify OIDC bypass reachability.
  • Plan controlled updates or disablement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Tugtainer?

Tugtainer is a self-hosted utility designed to automate the update process for Docker containers. By monitoring image repositories, it ensures your containerized environments stay up-to-date. Users typically deploy it to streamline maintenance workflows for container orchestration systems.

What does CVE-2026-55181 mean by authentication bypass?

This CVE involves a CWE-284 weakness, which concerns improper access control. Even if you have configured Tugtainer to disable OIDC authentication, the system fails to actually block the login process. A direct request can initiate the OIDC flow, effectively ignoring the setting meant to restrict access.

How is the OIDC login flow triggered in this CVE?

The flow is triggered when an unauthorized user sends a direct request to the specific login endpoint. Importantly, this occurs even when the administrative setting for OIDC is disabled. Simply checking the endpoint that reports OIDC status is not enough to prevent the login flow from starting.

Is my Tugtainer instance at risk?

According to Halo Surface Signal, this depends on your network configuration. If your Tugtainer instance is reachable via the internet, it is more likely to be accessible to external attackers. Instances restricted to local or VPN-only networks face a lower risk of reaching the login endpoint.

How do I address this Tugtainer vulnerability?

Your first step is to locate all Tugtainer instances in your environment and confirm their network accessibility. Once identified, plan to upgrade to version 1.30.3 or later, as this release contains the official fix that correctly enforces the OIDC disable switch.

References