Authentication Bypass Vulnerability in Prefect by PrefectHQ
CVE-2026-3514

7.5HIGH

Key Information:

Vendor

Prefecthq

Vendor
CVE Published:
2 June 2026

What is CVE-2026-3514?

In version 3.6.19 of Prefect by PrefectHQ, a significant vulnerability arises from the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware inadvertently permits any URL path that ends with 'health' or 'ready' to bypass authentication, allowing attackers to create resources with similar names and access them without any form of authentication. This vulnerability affects endpoints for various resources such as variables, flows, work pools, work queues, and deployments, leading to potential unauthorized access to sensitive information, including API keys and database credentials stored within Prefect Variables.

Affected Version(s)

prefecthq/prefect < 3.6.22

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.