PT-2026-6317 · Devtron · Devtron

B0B0Haha

+1

·

Published

2026-02-04

·

Updated

2026-02-06

·

CVE-2026-25538

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devtron versions prior to 2.0.0
Description Devtron is a tool integration platform for Kubernetes. A flaw exists in the Attributes API interface that allows authenticated users to obtain the global API Token signing key by accessing the /orchestrator/attributes?key=apiTokenSecret endpoint. Obtaining this key enables attackers to forge JWT tokens for arbitrary user identities offline, potentially granting complete control over the Devtron platform and allowing lateral movement to the underlying Kubernetes cluster. The issue was addressed with commit d2b0d26.
Recommendations Update to a version later than 2.0.0.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25538
GHSA-8WPC-J9Q9-J5M2
GO-2026-4416
SUSE-SU-2026:0403-1

Affected Products

Devtron