CVE-2026-55494 is an improper access control vulnerability in Tugtainer Agent before version 1.30.4. The Agent protects its API routes with request signatures, but its signature-verification function in agent/auth.py returns successfully when AGENT_SECRET is empty. Consequently, an Agent deployed without AGENT_SECRET configured exposes protected Docker management API routes without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, functional Python proof-of-concept for achieving RCE against Quenary Tugtainer v1.30.2 by chaining two vulnerabilities: CVE-2026-55494 and CVE-2026-62308. The repo contains five files: a README describing the bug chain and usage, a docker-compose lab environment, the main exploit script poc.py, a minimal requirements.txt listing requests, and a GPL license. The exploit flow in poc.py is straightforward and operational. It first authenticates to the target application using /api/auth/password/login with a supplied password. It then abuses the SSRF-capable /api/settings/test_notification endpoint by supplying an Apprise-style URL of json://127.0.0.1:8001<agent_path>, causing the application to send requests to an internal agent listening on localhost:8001. Through this internal unauthenticated agent, the script stops/removes any old container named 'pwn', creates a new helper container, and starts it. The core capability is remote shell command execution in the target container context. The helper container is created with :pid=container:tugtainer so it shares the PID namespace of the Tugtainer container. The attacker command is base64-encoded and wrapped as 'echo <b64>|base64 -d|sh', then passed as the health_cmd parameter. When the helper container starts, Docker executes the health check command, and because the helper container can access /proc/1/root, it can write into the Tugtainer container filesystem. The README demonstrates this by writing command output to /proc/1/root/tmp/pwned. This is not a detection script and not a fake exploit; it is a real exploit PoC with a basic but effective payload mechanism. It is not tied to a larger exploitation framework. The included docker-compose.yml provides a reproducible vulnerable environment featuring the Tugtainer container and a socket-proxy exposing Docker over tcp://socket-proxy:2375, which helps explain the intended deployment assumptions behind the exploit chain.
This repository is a small, functional Python proof-of-concept for remote code execution against Quenary Tugtainer v1.30.2. The repo contains 5 files: a GPL license, README, docker-compose lab setup, requirements.txt, and the main exploit script poc.py. The exploit is not part of a larger framework. The exploit chains multiple issues: it first authenticates to the Tugtainer web app using /api/auth/password/login, then abuses an SSRF primitive in /api/settings/test_notification by supplying an Apprise-style json://127.0.0.1:8001 URL. That SSRF reaches an internal agent listening on localhost:8001 which appears to expose unauthenticated container-management actions. Through this agent, the script stops/removes any prior container named pwn, creates a new container with PID namespace sharing against the tugtainer container (pid=container:tugtainer), sets an attacker-controlled Docker health_cmd, and starts the container. When Docker runs the health check, the supplied shell command executes. Because the helper container shares the target PID namespace, the exploit can access the target container filesystem via /proc/1/root and thereby achieve effective command execution in the Tugtainer container context. The payload handling is straightforward but practical: the user-supplied command is base64-encoded and wrapped as `echo <b64>|base64 -d|sh`, then URL-encoded into the health_cmd parameter to survive transport through the SSRF mechanism. This makes the exploit operational rather than a mere detection script. The README documents a reproducible Docker-based lab environment using ghcr.io/quenary/tugtainer:1.30.2 and a socket proxy on tcp://socket-proxy:2375, and demonstrates exploitation by writing command output to /proc/1/root/tmp/pwned. Overall purpose: demonstrate authenticated RCE in Tugtainer by chaining SSRF with an internal unauthenticated container-management service and Docker PID namespace abuse.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.