API Token Signing Key Vulnerability in Devtron Open Source Platform
CVE-2026-25538

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
4 February 2026

What is CVE-2026-25538?

Devtron, an open-source tool integration platform for Kubernetes, has a vulnerability in its Attributes API interface. In versions up to 2.0.0, any authenticated user, including low-privileged CI/CD Developers, can exploit this vulnerability by accessing the /orchestrator/attributes?key=apiTokenSecret endpoint. This access allows them to retrieve the global API Token signing key, which can then be used to forge JSON Web Tokens (JWT) for any user identity. This breach not only grants the attacker complete control over the Devtron platform but also enables lateral movement within the connected Kubernetes cluster, posing a significant security risk. The issue has been addressed in a recent patch.

Affected Version(s)

devtron <= 2.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.