PT-2026-6317 · Devtron · Devtron

·

CVE-2026-25538

·

Published

2026-02-04

·

Updated

2026-07-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devtron versions prior to 2.0.0
Description Devtron is a tool integration platform for Kubernetes. A flaw exists in the Attributes API interface that allows authenticated users to obtain the global API Token signing key by accessing the /orchestrator/attributes?key=apiTokenSecret endpoint. Obtaining this key enables attackers to forge JWT tokens for arbitrary user identities offline, potentially granting complete control over the Devtron platform and allowing lateral movement to the underlying Kubernetes cluster. The issue was addressed with commit d2b0d26.
Recommendations Update to a version later than 2.0.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25538
GHSA-8WPC-J9Q9-J5M2
GO-2026-4416
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0403-1

Affected Products

Devtron