PT-2026-6317 · Devtron · Devtron

B0B0Haha

+1

·

Publicado

2026-02-04

·

Atualizado

2026-02-06

·

CVE-2026-25538

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devtron versions prior to 2.0.0
Description Devtron is a tool integration platform for Kubernetes. A flaw exists in the Attributes API interface that allows authenticated users to obtain the global API Token signing key by accessing the /orchestrator/attributes?key=apiTokenSecret endpoint. Obtaining this key enables attackers to forge JWT tokens for arbitrary user identities offline, potentially granting complete control over the Devtron platform and allowing lateral movement to the underlying Kubernetes cluster. The issue was addressed with commit d2b0d26.
Recommendations Update to a version later than 2.0.0.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25538
GHSA-8WPC-J9Q9-J5M2
GO-2026-4416
SUSE-SU-2026:0403-1

Produtos afetados

Devtron