PT-2026-37260 · Devguard · Devguard

Published

2026-05-05

·

Updated

2026-05-20

·

CVE-2026-42300

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions DevGuard versions prior to 1.2.2
Description An authentication bypass exists in the SessionMiddleware where the system accepts a client-supplied X-Admin-Token HTTP request header. When no Kratos session cookie is present, the raw string value of this header is used as the authenticated userID. An unauthenticated attacker who possesses or guesses a target user's Kratos identity UUID can issue requests as that user. If the target user is an organization admin or owner, the attacker can gain full administrative control over the organization's resources.
Recommendations Update to version 1.2.2. Configure a reverse proxy to strip the X-Admin-Token header before sending requests to the API.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42300
GHSA-2G9V-7MR5-FGJG
GO-2026-4988

Affected Products

Devguard