Authentication Bypass in Kubero Notifications API
CVE-2026-92720
9.3CRITICAL
What is CVE-2026-92720?
Kubero version 3.1.1 is susceptible to an authentication bypass issue, which compromises the notifications API endpoints. Unsanctioned attackers can exploit this vulnerability to access sensitive data such as webhook secrets and service URLs without authentication. This breach enables them to not only retrieve stored credentials but also to add malicious webhooks that may compromise pipeline events and alert systems by deleting existing configurations. Users are advised to apply patches and implement security measures to safeguard their applications from potential exploitation.
Affected Version(s)
kubero 0 <= 3.1.1
