Authorization Bypass Vulnerability in Devtron Product by Devtron Labs
CVE-2026-82882
8.7HIGH
What is CVE-2026-82882?
An authorization bypass vulnerability exists in Devtron up to version 2.2.0, where authorization checks on the GET /orchestrator/api-token/webhook endpoint are inadequately enforced. This weakness enables authenticated users to make unauthorized requests, potentially retrieving plaintext super-admin JWT tokens. By exploiting this vulnerability with any authenticated account, an attacker can manipulate project, environment, and application parameters to gain elevated access and control over the platform.
Affected Version(s)
devtron 0 <= 2.2.0
