Authentication Bypass Vulnerability in Prefect by PrefectHQ
CVE-2026-3514
7.5HIGH
What is CVE-2026-3514?
In version 3.6.19 of Prefect by PrefectHQ, a significant vulnerability arises from the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware inadvertently permits any URL path that ends with 'health' or 'ready' to bypass authentication, allowing attackers to create resources with similar names and access them without any form of authentication. This vulnerability affects endpoints for various resources such as variables, flows, work pools, work queues, and deployments, leading to potential unauthorized access to sensitive information, including API keys and database credentials stored within Prefect Variables.
Affected Version(s)
prefecthq/prefect < 3.6.22
