Critical 9.8

Tugtainer agent auth bypass, no secret set (CVE-2026-55494) [PoC]

CVE-2026-55494

By Yazoul AI · automated

CVE-2026-55494: Tugtainer Agent before 1.30.4 skips signature checks when AGENT_SECRET is empty, exposing Docker management APIs unauthenticated. Update to 1.30.4.

Exploitation confirmed - public proof-of-concept - CVE-2026-55494 is a critical authentication bypass in Tugtainer Agent prior to version 1.30.4 that grants unauthenticated attackers full access to Docker management APIs when the AGENT_SECRET variable is left unset. Patched in 1.30.4 - update immediately if your agent runs without a configured secret.

Overview

Tugtainer is a self-hosted application that automates updates of Docker containers. It ships with an optional Agent component that exposes Docker management APIs over the network. Those routes are meant to be protected by request signatures validated in agent/auth.py.

The verification function in that file returns successfully whenever Config.AGENT_SECRET is empty. Instead of failing closed, the check fails open, so every protected Agent route becomes reachable without any credential. An attacker who can reach the Agent port needs no token, no signature, and no account.

Because the Agent speaks directly to the Docker daemon, exposure is severe. CVSS scores this 9.8: network reachable, low complexity, no privileges, no user interaction.

Impact

An unauthenticated attacker who can reach the Agent API effectively controls the Docker host:

  • Start, stop, and remove arbitrary containers.
  • Create new containers from any image, which is a straightforward path to running code on the host.
  • Inspect images, networks, volumes, and container configuration.
  • Reach environment variables and mount points that frequently hold credentials, database passwords, and API keys.

Deployments that bind the Agent to a public interface and skipped AGENT_SECRET are the highest risk. Internal-only deployments are still exposed to any compromised host on the same network.

Remediation and Mitigation

  1. Upgrade Tugtainer Agent to 1.30.4 or later. The patch makes signature verification fail when no secret is configured.
  2. Set AGENT_SECRET to a long, random value on every Agent instance and every client that talks to it. Leaving it empty is what triggers the bypass on older builds.
  3. Restrict the Agent port with firewall rules or bind it to localhost or a private interface. Never expose it directly to the internet.
  4. Rotate any credentials, tokens, or keys that were reachable from containers or their environment on exposed hosts, since unauthorized container inspection may have leaked them.
  5. Review Docker audit logs and container events for unexpected create, start, or exec activity.

If you cannot upgrade immediately, configuring a non-empty AGENT_SECRET and network-restricting the port are the fastest interim mitigations. Breach disclosure guidance is available at breach reports and ongoing coverage at security news.

Security Insight

This is another instance of the fail-open anti-pattern: a security control that treats “not configured” as “authorized” rather than “denied.” Signature verification is only as strong as its default branch, and returning success on an empty secret turns an optional setting into a silent backdoor. Self-hosted tooling with direct Docker socket access deserves the same hardening scrutiny as internet-facing infrastructure, because a single misconfigured environment variable collapses the entire trust boundary.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
4qu4r1um/tugtainer-1.30.2-CVE-2026-55494-and-CVE-2026-62308-to-RCE

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

★ 0

Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.