Authorization Bypass Vulnerability in Devtron Product by Devtron Labs
CVE-2026-82882

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82882?

An authorization bypass vulnerability exists in Devtron up to version 2.2.0, where authorization checks on the GET /orchestrator/api-token/webhook endpoint are inadequately enforced. This weakness enables authenticated users to make unauthorized requests, potentially retrieving plaintext super-admin JWT tokens. By exploiting this vulnerability with any authenticated account, an attacker can manipulate project, environment, and application parameters to gain elevated access and control over the platform.

Affected Version(s)

devtron 0 <= 2.2.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.