PT-2026-37260 · Devguard · Devguard
Published
2026-05-05
·
Updated
2026-05-20
·
CVE-2026-42300
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
DevGuard versions prior to 1.2.2
Description
An authentication bypass exists in the
SessionMiddleware where the system accepts a client-supplied X-Admin-Token HTTP request header. When no Kratos session cookie is present, the raw string value of this header is used as the authenticated userID. An unauthenticated attacker who possesses or guesses a target user's Kratos identity UUID can issue requests as that user. If the target user is an organization admin or owner, the attacker can gain full administrative control over the organization's resources.Recommendations
Update to version 1.2.2.
Configure a reverse proxy to strip the
X-Admin-Token header before sending requests to the API.Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devguard