API Token Signing Key Vulnerability in Devtron Open Source Platform
CVE-2026-25538
8.7HIGH
What is CVE-2026-25538?
Devtron, an open-source tool integration platform for Kubernetes, has a vulnerability in its Attributes API interface. In versions up to 2.0.0, any authenticated user, including low-privileged CI/CD Developers, can exploit this vulnerability by accessing the /orchestrator/attributes?key=apiTokenSecret endpoint. This access allows them to retrieve the global API Token signing key, which can then be used to forge JSON Web Tokens (JWT) for any user identity. This breach not only grants the attacker complete control over the Devtron platform but also enables lateral movement within the connected Kubernetes cluster, posing a significant security risk. The issue has been addressed in a recent patch.
Affected Version(s)
devtron <= 2.0.0
