{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adevtrondevtron/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:devtron:devtron:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-82882"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Devtron (\u003c= 2.2.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","credential-access"],"_cs_type":"advisory","_cs_vendors":["Devtron"],"content_html":"\u003cp\u003eDevtron versions 2.2.0 and earlier are affected by an authorization bypass vulnerability (CVE-2026-82882) located in the orchestrator webhook API. The vulnerability specifically affects the GET /orchestrator/api-token/webhook endpoint, which fails to validate the authorization level of the requesting user. An authenticated attacker, regardless of their original privilege level, can provide arbitrary project, environment, and application parameters to the endpoint to successfully query for and retrieve super-admin JSON Web Tokens (JWT) in plaintext. Successful exploitation provides the attacker with full platform control, enabling persistent access, configuration modifications, or unauthorized deployments within the Devtron environment. This vulnerability is critical for organizations using Devtron to manage CI/CD pipelines, as it allows for trivial privilege escalation to the highest administrative tier.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full administrative control over the Devtron platform. Attackers can leverage the stolen super-admin tokens to perform any action the platform supports, including modifying deployment pipelines, accessing sensitive secrets managed by the platform, and pivoting into the underlying Kubernetes infrastructure. This allows for extensive persistence, data exfiltration, and potential supply chain compromise of the integrated CI/CD processes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Devtron instances to a version later than 2.2.0 immediately once a vendor patch is made available.\u003c/li\u003e\n\u003cli\u003eImplement strict monitoring on access to the /orchestrator/api-token/webhook endpoint in API gateway or web server logs.\u003c/li\u003e\n\u003cli\u003eRotate all administrative tokens if it is suspected that an unauthorized user has accessed the platform.\u003c/li\u003e\n\u003cli\u003ePerform an audit of audit logs to identify any anomalous access to the webhook API endpoint by non-administrative user accounts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T01:01:31Z","date_published":"2026-09-01T01:01:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-devtron-auth-bypass/","summary":"Devtron versions 2.2.0 and earlier contain an authorization flaw in the orchestrator webhook endpoint that allows authenticated users to retrieve plaintext super-admin API tokens.","title":"Devtron Authorization Bypass in Webhook API","url":"https://feed.craftedsignal.io/briefs/2026-09-devtron-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:devtron:devtron:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}