CVE-2026-62308 is an authenticated blind server-side request forgery vulnerability in Tugtainer versions before 1.30.6. The notification-test functionality accepts a user-controlled URL list and passes supplied destinations to Apprise without restrictions on protocols, hostnames, loopback addresses, private address ranges, or cloud metadata services. An authenticated user can thereby cause the Tugtainer backend to issue outbound HTTP requests to arbitrary supplied destinations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, functional Python proof-of-concept for achieving RCE against Quenary Tugtainer v1.30.2 by chaining two vulnerabilities: CVE-2026-55494 and CVE-2026-62308. The repo contains five files: a README describing the bug chain and usage, a docker-compose lab environment, the main exploit script poc.py, a minimal requirements.txt listing requests, and a GPL license. The exploit flow in poc.py is straightforward and operational. It first authenticates to the target application using /api/auth/password/login with a supplied password. It then abuses the SSRF-capable /api/settings/test_notification endpoint by supplying an Apprise-style URL of json://127.0.0.1:8001<agent_path>, causing the application to send requests to an internal agent listening on localhost:8001. Through this internal unauthenticated agent, the script stops/removes any old container named 'pwn', creates a new helper container, and starts it. The core capability is remote shell command execution in the target container context. The helper container is created with :pid=container:tugtainer so it shares the PID namespace of the Tugtainer container. The attacker command is base64-encoded and wrapped as 'echo <b64>|base64 -d|sh', then passed as the health_cmd parameter. When the helper container starts, Docker executes the health check command, and because the helper container can access /proc/1/root, it can write into the Tugtainer container filesystem. The README demonstrates this by writing command output to /proc/1/root/tmp/pwned. This is not a detection script and not a fake exploit; it is a real exploit PoC with a basic but effective payload mechanism. It is not tied to a larger exploitation framework. The included docker-compose.yml provides a reproducible vulnerable environment featuring the Tugtainer container and a socket-proxy exposing Docker over tcp://socket-proxy:2375, which helps explain the intended deployment assumptions behind the exploit chain.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.